Impact
Ghost versions prior to 6.20.0 allow unauthenticated attackers to read theme templates and metadata by bypassing file extension validation through URL encoding. This flaw enables the disclosure of potentially sensitive configuration files used by the CMS. The vulnerability is identified as a file read flaw (CWE‑173) and can be exploited remotely without authentication.
Affected Systems
All installations of Ghost older than 6.20.0 are susceptible. The affected product is the Ghost content management system (TryGhost:Ghost).
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. No EPSS data is available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited, if any, current exploitation in the wild. Attackers can exploit this remotely over the network by crafting a request containing URL‑encoded characters to trigger the bypass. Because no authentication is required, any external user can access the sensitive files if the CMS is exposed publicly.
OpenCVE Enrichment