Description
Ghost versions 6.14.0 through versions prior to 6.27.0 contain a path traversal vulnerability in the ImageSize service. Insufficient input validation of user-supplied file paths may allow authenticated staff users to access local files outside the intended data storage directories on the server.
Published: 2026-10-01
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: Local File Disclosure
Action: Upgrade
AI Analysis

Impact

The vulnerability resides in the ImageSize service of Ghost, where user-supplied file paths are not properly validated. This flaw permits authenticated staff users to request file paths that traverse outside the designated data storage directories, enabling them to read sensitive files on the host. The weakness is classified as CWE-35, representing path traversal. The exposed capability is local file disclosure, which can reveal system configuration, credentials, or other confidential data stored on the server.

Affected Systems

TryGhost Ghost versions 6.14.0 through any release prior to 6.27.0 are affected. Users deploying these releases should verify they are on or after the 6.27.0 patch that removes the path traversal flaw.

Risk and Exploitability

The CVSS base score is 5.1, indicating a moderate risk level. Because the EPSS score is not available, the historical exploitation likelihood cannot be precisely quantified; however, the flaw is not listed in CISA’s Known Exploited Vulnerabilities catalog. Attackers would need to authenticate as a staff member or gain similar privileges to exploit the issue. If an authenticated user can trigger the ImageSize service, they can arbitrarily read files outside the intended folders, potentially escalating their access or gathering sensitive information.

Generated by OpenCVE AI on October 1, 2026 at 14:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Ghost to version 6.27.0 or later to eliminate the path traversal flaw
  • Restrict staff accounts from executing the ImageSize service or limit file path inputs through application-level whitelisting
  • Apply stringent input validation for all file path parameters in the Ghost codebase, ensuring that traversals such as '..' are sanitized before use

Generated by OpenCVE AI on October 1, 2026 at 14:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description Ghost versions 6.14.0 through versions prior to 6.27.0 contain a path traversal vulnerability in the ImageSize service. Insufficient input validation of user-supplied file paths may allow authenticated staff users to access local files outside the intended data storage directories on the server.
Title Ghost 6.14.0 before 6.27.0 Path Traversal via ImageSize
First Time appeared Ghost
Ghost ghost
Weaknesses CWE-35
CPEs cpe:2.3:a:ghost:ghost:*:*:*:*:*:*:*:*
Vendors & Products Ghost
Ghost ghost
References
Metrics cvssV3_1

{'score': 3.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:L'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T14:37:50.738Z

Reserved: 2026-09-30T10:59:26.443Z

Link: CVE-2026-103290

cve-icon Vulnrichment

Updated: 2026-10-01T14:37:47.640Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T11:17:25.520

Modified: 2026-10-01T15:17:27.367

Link: CVE-2026-103290

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T20:15:11Z

Weaknesses
  • CWE-35

    Path Traversal: '.../...//'