Executive brief
Ghost is a popular open-source publishing platform used for blogs, newsletters, and membership sites. An arbitrary file upload vulnerability allows attackers to upload malicious SVG files to execute arbitrary code on the server, potentially compromising the entire platform and any data it manages.
Technical details
This is a CWE-434 (Unrestricted Upload of File with Dangerous Type) vulnerability in Ghost's file upload module. The vulnerability exists in version 4.39.0 and earlier, where insufficient validation of uploaded files allows attackers to bypass security checks by uploading a crafted SVG file containing executable code. The attack requires network access to the file upload endpoint with no authentication or user interaction required. A successful exploit results in arbitrary code execution on the server with the privileges of the Ghost process, enabling data theft, platform compromise, and lateral movement within the infrastructure. Patches should be available in versions after 4.39.0.
Affected products
- Ghost Ghost 0 to 4.39.0
Timeline
- 2022-04-13: disclosed
- 2022-04-12: other: NVD published