CRITICAL🇵🇱 Wersja polska

CVE-2026-53943

CVSS 9.6v3.1pub. 2026-06-24upd. 2026-06-25

Ghost is a Node.js content management system. From until 6.37.0, when Ghost is behind a shared caching layer that results in cached content being shared between different visitors, an unauthenticated user could send an x-ghost-preview header that altered the rendered frontend response. In affected cache configurations, that response could be stored and served to subsequent visitors requesting the same page, allowing cache poisoning of request-specific preview output. When running Ghost's frontend and admin panel on the same domain this could be used to take over staff user accounts. When running these on different domains staff accounts have no exposure. This vulnerability is fixed in 6.37.0.

🤖 AI Analysis
How it works

When Ghost runs behind a shared cache layer, an attacker can send a crafted x-ghost-preview header that modifies the rendered frontend response. The modified response can be stored in the cache and subsequently served to subsequent users visiting the same page. In a configuration where Ghost frontend and admin panel run on the same domain, this mechanism can be exploited to take over staff accounts.

Impact

An attacker can poison the service cache and serve malicious content to unsuspecting users, and in a specific domain configuration can take over Ghost CMS staff user accounts.

Mitigation & patch

Ghost CMS should be updated to version 6.37.0 or newer, where the vulnerability has been fixed. As a workaround, running the frontend and admin panel on separate domains eliminates the risk of staff account takeover.

Who is affected

Ghost CMS in versions below 6.37.0, running behind a shared cache layer; account takeover vulnerability applies only to configurations where frontend and admin panel are served on the same domain

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References