Path traversal in Ghost - CVE-2026-70593
Published: July 30, 2026
Vulnerability details
The vulnerability allows a remote user to modify files outside the intended upload directory and alter the behavior of the installation.
The vulnerability exists due to path traversal in the theme upload feature when uploading custom themes. A remote privileged user can upload a specially crafted theme to modify files outside the intended upload directory and alter the behavior of the installation.