# Security update available for Ghost 4.x and 5.x

**URL:** <https://forum.ghost.org/t/security-update-available-for-ghost-4-x-and-5-x/30823>\
**Category:** News\
**Created:** [June 15, 2022, 10:21pm UTC](https://forum.ghost.org/t/security-update-available-for-ghost-4-x-and-5-x/30823 "2022-06-15T22:21:43Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![matthanley](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/matthanley/32/8206_2.png) [@matthanley](https://forum.ghost.org/u/matthanley)\
**Post date:** [June 15, 2022, 10:21pm UTC](https://forum.ghost.org/t/security-update-available-for-ghost-4-x-and-5-x/30823/1 "2022-06-15T22:21:43Z")

</div>

We’ve been made aware of a security vulnerability in Ghost versions 4.x prior to 4.48.2 and 5.x prior to 5.2.3. This is patched in the latest releases, which have already been rolled out on Ghost(Pro). Self-hosters should update to 5.2.3 (or 4.48.2 for those still on v4) as soon as possible.

**Details:**

A [vulnerability](https://www.cve.org/CVERecord?id=CVE-2022-24785) in an upstream library means an authenticated Admin user can abuse locale input to execute arbitrary commands from a file that has previously been uploaded using the file upload functionality in the post editor.

**Ghost(Pro):**

Ghost(Pro) has already been patched. As Ghost(Pro) is maintained by the Ghost core team, it is always patched immediately when any security incident is reported.

**Patch & Workarounds:**

Patched versions of Ghost add validation to the locale input to prevent execution of arbitrary files. Updating Ghost is the quickest complete solution.

As a workaround, if for any reason you cannot update your Ghost instance, you can block the `POST /ghost/api/admin/settings/`endpoint, which will also disable updating settings for your site.

**Disclosure:**

Full details of the vulnerability have been published through [GitHub Advisories](https://github.com/TryGhost/Ghost/security/advisories/GHSA-7v28-g2pq-ggg8). We’ve also published a notification to all affected sites that will appear in Ghost Admin and shared the details here on the forum. Affected Ghost sites will also self-notify site owners by email.

We’re grateful to everyone finding and reporting vulnerabilities responsibly following our [security policy](https://ghost.org/docs/security/#reporting-vulnerabilities).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex015/uploads/ghost2/original/2X/b/ba9ce5100b8bb264586f4f572545596b2ce3f081.png) [@system](https://forum.ghost.org/u/system)\
**Post date:** [June 29, 2022, 10:22pm UTC](https://forum.ghost.org/t/security-update-available-for-ghost-4-x-and-5-x/30823/2 "2022-06-29T22:22:39Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
