Improper Handling of Alternate Encoding in Ghost - #VU142539
Published: August 14, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper handling of alternate encoding in theme file serving when processing URL-encoded requests. A remote attacker can send a specially crafted request to disclose sensitive information.
The issue can expose theme templates and metadata.