Insufficient validation of the client-supplied Content-Type on Ghost's Admin API file upload endpoint allowed uploaded files to be served from the site with an attacker-chosen content type on S3/GCS storage backends. On installations that serve uploaded files from the same origin as the site, this could have been used to facilitate stored cross-site scripting against site visitors or staff.
This vulnerability is present in Ghost from v6.19.4 up to v6.21.0.
v6.21.1 contains a fix for this issue.
For self-hosters using Docker, find Docker's official Ghost image here. Updating a Docker-based Ghost instance is documented here.
If your Ghost is a Ghost-CLI install see our documentation on updating it to the latest version here.
If you have any questions or comments about this advisory, email us at security@ghost.org.
{
"nvd_published_at": "2026-06-24T19:17:12Z",
"cwe_ids": [
"CWE-434"
],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2026-08-04T21:05:39Z"
}