Impact
Ghost allows a staff user to upload custom themes that can traverse the file system and write arbitrary files outside the designated uploads directory. This path‑traversal flaw, classified as CWE‑22, enables an attacker with staff permissions to modify or drop server files, potentially leading to compromised application logic or execution of malicious code.
Affected Systems
The flaw affects all Ghost installations built with TryGhost:Ghost versions from 0.10.0 up to but not including 6.54.1. Users running any of those releases are at risk until the fix is applied.
Risk and Exploitability
The CVSS score of 6.6 indicates a moderate severity. Although the EPSS score is not published and the vulnerability is not listed in CISA’s KEV catalog, the ability to write files as a staff user remains a significant risk because it leverages legitimate, high‑privilege accounts. An attacker who gains staff access can immediately exploit the flaw to alter site behavior or execute code, so the threat should be considered as soon as a vulnerable version is in use.
OpenCVE Enrichment
Github GHSA