CVE-2026-105683
LOW
3,8
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: high
User Interaction: none
Scope: unchanged
Confidentiality: low
Integrity: none
Availability: low
Description
AI Translation Available
Ghost is a Node.js content management system. From 6.14.0 until 6.27.0, an input validation issue may have allowed staff users to access local files outside the intended data storage directories on the server. This issue is fixed in version 6.27.0.
35
Path Traversal: '.../...//'
IncompleteCommon Consequences
Security Scopes Affected:
Confidentiality
Integrity
Potential Impacts:
Read Files Or Directories
Modify Files Or Directories
Bypass Protection Mechanism
Applicable Platforms
All platforms may be affected
https://github.com/TryGhost/Ghost/commit/770d438fd9d352bbfccbe81dd890580a1d3fd6…
https://github.com/TryGhost/Ghost/pull/27217
https://github.com/TryGhost/Ghost/releases/tag/v6.27.0
https://github.com/TryGhost/Ghost/security/advisories/GHSA-83rp-q473-j88c