Impact
An input validation flaw in Ghost's ImageSize Service allows authenticated staff users to construct requests that traverse directories and read files outside the standard data storage location. The flaw can expose sensitive content stored on the server, potentially leaking configuration, credentials, or other confidential data, as demonstrated by the ability to read arbitrary files.
Affected Systems
The vulnerability affects Ghost, a Node.js content management system maintained by TryGhost. Versions from 6.14.0 through, but not including, 6.27.0 are impacted. Users running any of these releases should review their deployment and ensure they are not using older or unsupported versions.
Risk and Exploitability
The CVSS score is 3.8, indicating a low‑to‑moderate severity. Although no EPSS score is provided, the lack of inclusion in the CISA KEV catalog suggests limited active exploitation. The attack requires a staff‑level account with access to the ghost ImageSize endpoint, and can be performed locally within the application. Upgrading to 6.27.0 eliminates the flaw and should be pursued as the primary mitigation.
OpenCVE Enrichment