THREAT OPS › Threat News › [GHSA] GHSA-944x-pm95-3jpr (medium) — Ghost: File Upload Content-Type Spoofing
[GHSA] GHSA-944x-pm95-3jpr (medium) — Ghost: File Upload Content-Type Spoofing
GHSA-944x-pm95-3jpr Severity: medium CVE: CVE-2026-53948
Ghost: File Upload Content-Type Spoofing
### Impact
Insufficient validation of the client-supplied `Content-Type` on Ghost's Admin API file upload endpoint allowed uploaded files to be served from the site with an attacker-chosen content type on S3/GCS storage backends. On installations that serve uploaded files from the same origin as th
Indicators of compromise
- CVE-2026-53948cve
- https://hub.docker.com/_/ghosturl
- https://docs.ghost.org/install/docker#updating-ghosturl
- https://docs.ghost.org/updateurl
- security@ghost.orgemail
Original source: https://github.com/advisories/GHSA-944x-pm95-3jpr