CVE-2026-103290
Received Received - Intake

Path Traversal in Ghost CMS via ImageSize Service

Vulnerability report for CVE-2026-103290, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: VulnCheck

Description

Ghost versions 6.14.0 through versions prior to 6.27.0 contain a path traversal vulnerability in the ImageSize service. Insufficient input validation of user-supplied file paths may allow authenticated staff users to access local files outside the intended data storage directories on the server.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ghost ghost to 6.27.0 (exc)
tryghost ghost From 6.14.0 (inc) to 6.27.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-35 The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a path traversal vulnerability in Ghost versions 6.14.0 through 6.27.0. It affects the ImageSize service where insufficient input validation of file paths allows authenticated staff users to access local files outside intended storage directories on the server.

Detection Guidance

To detect this vulnerability, check if your Ghost installation is running a version between 6.14.0 and 6.27.0. Use commands like 'ghost version' or check package.json for the version. If the version is within this range, the system is vulnerable.

Impact Analysis

An attacker with staff user access could read sensitive files on the server outside the intended directories. This may lead to unauthorized data exposure or information leakage, depending on the files accessed.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, potentially violating compliance requirements like GDPR or HIPAA which mandate strict data protection and access controls.

Mitigation Strategies

Immediately update Ghost to version 6.27.0 or later. Use commands like 'ghost update' or follow the official Ghost upgrade guide. Ensure no unauthorized file access has occurred during the vulnerable period.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103290. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart