CVE-2026-103276
Received
Received - Intake
Ghost CMS Theme Template File Disclosure via URL Encoding
Vulnerability report for CVE-2026-103276, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-01
Last updated on: 2026-10-01
Assigner: VulnCheck
Description
Description
Ghost versions before 6.20.0 contain a file extension filtering bypass vulnerability that allows unauthenticated attackers to read theme templates and metadata. Attackers can use URL encoding to bypass extension validation and access sensitive theme files.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ghost | ghost | to 6.20.0 (exc) |
| tryghost | ghost | to 6.20.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-173 | The product does not properly handle when an input uses an alternate encoding that is valid for the control sphere to which the input is being sent. |