Ghost is a Node.js content management system. From 6.14.0 until 6.27.0, an input validation issue may have allowed staff users to access local files outside the intended data storage directories on the server. This issue is fixed in version 6.27.0.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 05 Oct 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Ghost is a Node.js content management system. From 6.14.0 until 6.27.0, an input validation issue may have allowed staff users to access local files outside the intended data storage directories on the server. This issue is fixed in version 6.27.0. | |
| Title | Ghost: Path Traversal Vulnerability in Ghost ImageSize Service | |
| Weaknesses | CWE-35 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-05T19:31:28.855Z
Reserved: 2026-10-05T17:48:58.626Z
Link: CVE-2026-105683
No data.
Status : Received
Published: 2026-10-05T20:17:17.123
Modified: 2026-10-05T20:17:17.123
Link: CVE-2026-105683
No data.
OpenCVE Enrichment
Updated: 2026-10-05T21:15:15Z
Weaknesses