Impact
The vulnerability resides in the ImageSize service of Ghost, where user-supplied file paths are not properly validated. This flaw permits authenticated staff users to request file paths that traverse outside the designated data storage directories, enabling them to read sensitive files on the host. The weakness is classified as CWE-35, representing path traversal. The exposed capability is local file disclosure, which can reveal system configuration, credentials, or other confidential data stored on the server.
Affected Systems
TryGhost Ghost versions 6.14.0 through any release prior to 6.27.0 are affected. Users deploying these releases should verify they are on or after the 6.27.0 patch that removes the path traversal flaw.
Risk and Exploitability
The CVSS base score is 5.1, indicating a moderate risk level. Because the EPSS score is not available, the historical exploitation likelihood cannot be precisely quantified; however, the flaw is not listed in CISA’s Known Exploited Vulnerabilities catalog. Attackers would need to authenticate as a staff member or gain similar privileges to exploit the issue. If an authenticated user can trigger the ImageSize service, they can arbitrarily read files outside the intended folders, potentially escalating their access or gathering sensitive information.
OpenCVE Enrichment