CVE-2026-53943 Details
Description
Ghost is a Node.js content management system. From until 6.37.0, when Ghost is behind a shared caching layer that results in cached content being shared between different visitors, an unauthenticated user could send an x-ghost-preview header that altered the rendered frontend response. In affected cache configurations, that response could be stored and served to subsequent visitors requesting the same page, allowing cache poisoning of request-specific preview output. When running Ghost's frontend and admin panel on the same domain this could be used to take over staff user accounts. When running these on different domains staff accounts have no exposure. This vulnerability is fixed in 6.37.0.
A cache poisoning vulnerability has been identified in Ghost, a Node.js content management system, affecting versions 4.0.0 prior to 6.36.0. The issue arises when Ghost is behind a shared caching layer that distributes cached content among different visitors. In these configurations, an unauthenticated user can send an x-ghost-preview header that modifies the rendered frontend response. This altered response may be cached and served to subsequent visitors, poisoning the cache with request-specific preview output. If Ghost's frontend and admin panel are on the same domain, this vulnerability could be exploited to take over staff user accounts. However, if they are on different domains, there is no exposure.
Users can update to Ghost version 6.37.0, which addresses this vulnerability. For self-hosters using Docker, instructions for updating a Docker-based Ghost instance are available in the Ghost documentation. If Ghost is installed using Ghost-CLI, see the documentation on updating to the latest version. If a credential compromise is suspected, use the 'Reset all authentication' dialogue under Settings / Danger Zone, available starting with Ghost v6.41.0.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 24, 2026CISA-ADP
Assessed Jun 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/TryGhost/Ghost/security/advisories/GHSA-62q6-4hv4-vjrw | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-524 | Use of Cache Containing Sensitive Information | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Ghost | >= 4.0.0, <= 6.36.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 24, 2026 | New CVE Received | [email protected] |
| Jun 24, 2026 | CVE Modified | CISA-ADP |
Volerion