Path traversal in Ghost - CVE-2026-70593

 

Path traversal in Ghost - CVE-2026-70593

Published: July 30, 2026


Vulnerability identifier: #VU140547
CSH Severity: Low
CVSS v4: 5.9 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-70593
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to modify files outside the intended upload directory and alter the behavior of the installation.

The vulnerability exists due to path traversal in the theme upload feature when uploading custom themes. A remote privileged user can upload a specially crafted theme to modify files outside the intended upload directory and alter the behavior of the installation.


Affected software

Ghost

How to mitigate CVE-2026-70593

Install security update from vendor's website.

Ghost - update to 6.54.1

External References

Related Security Bulletins