Relative Path Traversal in Ghost - #VU142541
Published: August 14, 2026
Vulnerability details
The vulnerability allows a remote user to take over a staff user\'s account.
The vulnerability exists due to relative path traversal in the admin iframe when processing published content. A remote user can publish a malicious page to take over a staff user\'s account.
User interaction is required for an active staff user to visit the malicious page.