Ghost Admin Universal Import Feature Vulnerable to XSS
The Universal Import feature in Ghost Admin reportedly failed to properly sanitize imported content, resulting in a potential Cross-Site Scripting (XSS) vulnerability. Versions from v5.26.0 up to v6.54.0 are under investigation.
What happened
An early warning has been issued regarding a potential Cross-Site Scripting (XSS) vulnerability in the Universal Import feature of Ghost Admin. This vulnerability appears to stem from inadequate sanitization of imported content, which could allow malicious scripts to be executed. Versions of Ghost Admin from v5.26.0 up to v6.54.0 are reportedly affected.
To assess your exposure, check if your Ghost Admin installation falls within the affected version range (v5.26.0 - v6.54.0). If so, it is recommended to upgrade to Ghost v6.54.1 as a precautionary measure. Alternatively, avoid using the Universal Import feature until the issue is resolved.
For more detailed information, consult the primary source at [GHSA-2gx6-7gx2-wwcf](https://github.com/TryGhost/Ghost/security/advisories/GHSA-2gx6-7gx2-wwcf). The situation is still under investigation, and further updates may be forthcoming.
How 0Day mitigates this
ghost is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.