Path Traversal: \'.../...//\' in Ghost - #VU142536
Published: August 14, 2026
Vulnerability details
The vulnerability allows a remote user to disclose local files outside the intended data storage directories.
The vulnerability exists due to path traversal in ImageSize Service when processing user-supplied file paths. A remote privileged user can supply a crafted path to disclose local files outside the intended data storage directories.