Back

LOW

Ghost: Path Traversal Vulnerability in Ghost ImageSize Service

Published Oct 5, 2026

Description

Ghost is a Node.js content management system. From 6.14.0 until 6.27.0, an input validation issue may have allowed staff users to access local files outside the intended data storage directories on the server. This issue is fixed in version 6.27.0.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Oct 5, 2026
Updated Oct 5, 2026
Reserved Oct 5, 2026

CISA Vulnrichment

No data

NVD

Status Deferred
Modified Oct 6, 2026

Red Hat

No data

ENISA EUVD

Assigner GitHub_M
Published Oct 5, 2026
Updated Oct 5, 2026