Description
Ghost is a Node.js content management system. From 6.14.0 until 6.27.0, an input validation issue may have allowed staff users to access local files outside the intended data storage directories on the server. This issue is fixed in version 6.27.0.
Published: 2026-10-05
Score: 3.8 Low
EPSS: n/a
KEV: No
Impact: Local File Disclosure
Action: Patch
AI Analysis

Impact

An input validation flaw in Ghost's ImageSize Service allows authenticated staff users to construct requests that traverse directories and read files outside the standard data storage location. The flaw can expose sensitive content stored on the server, potentially leaking configuration, credentials, or other confidential data, as demonstrated by the ability to read arbitrary files.

Affected Systems

The vulnerability affects Ghost, a Node.js content management system maintained by TryGhost. Versions from 6.14.0 through, but not including, 6.27.0 are impacted. Users running any of these releases should review their deployment and ensure they are not using older or unsupported versions.

Risk and Exploitability

The CVSS score is 3.8, indicating a low‑to‑moderate severity. Although no EPSS score is provided, the lack of inclusion in the CISA KEV catalog suggests limited active exploitation. The attack requires a staff‑level account with access to the ghost ImageSize endpoint, and can be performed locally within the application. Upgrading to 6.27.0 eliminates the flaw and should be pursued as the primary mitigation.

Generated by OpenCVE AI on October 5, 2026 at 21:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Ghost to version 6.27.0 or later, which removes the input validation flaw.
  • Verify legacy image configurations to ensure no references to insecure file paths remain after the upgrade.
  • If an immediate upgrade is not possible, limit staff access to directories that could be exploited by restricting filesystem permissions or isolating content directories to prevent traversal beyond the intended scope.

Generated by OpenCVE AI on October 5, 2026 at 21:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 20:15:00 +0000

Type Values Removed Values Added
Description Ghost is a Node.js content management system. From 6.14.0 until 6.27.0, an input validation issue may have allowed staff users to access local files outside the intended data storage directories on the server. This issue is fixed in version 6.27.0.
Title Ghost: Path Traversal Vulnerability in Ghost ImageSize Service
Weaknesses CWE-35
References
Metrics cvssV3_1

{'score': 3.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-05T19:31:28.855Z

Reserved: 2026-10-05T17:48:58.626Z

Link: CVE-2026-105683

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T20:17:17.123

Modified: 2026-10-05T20:17:17.123

Link: CVE-2026-105683

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T21:15:15Z

Weaknesses
  • CWE-35

    Path Traversal: '.../...//'