Skip to content

Ghost

v6.54.0 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 2d Productivity & Wikis
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

blogging cms ghost javascript journalism nodejs
+2 more
publishing web

Affected surfaces

deps

Summary

AI summary

Filename generation hardened against filesystem limits and security risks.

Full changelog
  • 🔒 Made filename generation more secure, performant and resilient to filesystems' limits (#70) - Sag
  • ✨ Added config to specify custom adapter install location (#29487) - Austin Burdine
  • ✨ Added inline editor for redirects.yaml and routes.yaml (#29200) - Murat Çorlu
  • ✨ Added support for v4 (canary) schema - Naz
  • ✨ Added member.avatar_image for member gravatars in themes (#11584) - Kevin Ansfield
  • ✨Added labels for Members (#11538) - Rishabh Garg
  • ✨ Added complimentary member subscription (#11537) - Naz Gargol
  • ✨ Added posibility to accept html as an input source for post - Nazar Gargol
  • ✨ add storage base (#1) - Katharina Irrgang
  • 🎨 Removed unused base adapter shims (#29564) - Austin Burdine
  • 🎨 Changed pre-launch banner copy and link to be configurable via hostSettings (#29540) - Jannis Fedoruk-Betschki
  • 🎨 Updated settings chooser controls (#29503) - Steve Larson
  • 🎨 Further improved automation polling performance (#29477) - Evan Hahn
  • 🎨 Improved automation polling performance (#29476) - Evan Hahn
  • 🐛 Fixed unsafe output from the split helper (#29298) - Oscar Hedvall
  • 🐛 Fixed posts with a self-referential canonical URL being excluded from the sitemap - yash
  • 🐛 Fixed YouTube bookmark metadata (#29114) - Rayan Salhab
  • 🐛 Fixed a members import label containing a comma being split in two - Rob Lester
  • 🐛 Fixed members CSV import storing a formula-escape character in member data - Rob Lester
  • 🐛 Fixed members CSV import dropping columns from an uneven file - Rob Lester
  • 🐛 Fixed member custom field actions breaking history (#29506) - Steve Larson
  • 🐛 Fixed dark mode loader showing a white background (#29340) - sarafmudit
  • 🐛 Fixed incorrect audio durations after HTML import (#29337) - Kushida
  • 🐛 Fixed theme toggle crossfade in the standalone React admin (#29458) - Steve Larson
  • 🐛 Fixed extention missmatching .mp4 as invalid - Naz
  • 🐛 Fixed $id clash when validating across different API versions (#349) - naz
  • 🐛 Fixed CSV import json-schema email validation (#12239) - Fabien 'egg' O'Carroll
  • 🐛 Fixed validation error when adding tag from PSM - Nazar Gargol
  • 💡 Added canary api endpoint - Rish

View the changelog for full details: https://github.com/TryGhost/Ghost/compare/v6.53.0...v6.54.0

Security Fixes

  • Filename generation made more secure, performant and resilient to filesystem limits (addresses potential injection/overflow risks)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Ghost

Get notified when new releases ship.

Sign up free

About Ghost

Independent technology for modern publishing, memberships, subscriptions and newsletters.

All releases →

Related context

Beta — feedback welcome: [email protected]