CVE-2026-103276: Ghost before 6.20.0 File Read via URL Encoding Bypass
Ghost versions before 6.20.0 contain a file extension filtering bypass vulnerability that allows unauthenticated attackers to read theme templates and metadata. Attackers can use URL encoding to bypass extension validation and access sensitive theme files.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ghostto a version that resolves this vulnerability.Fixed in 6.20.0
Event History
Frequently Asked Questions
Which deployments are affected?
Ghost versions before 6.20.0 are affected. The issue exposes theme templates and metadata through a file-extension filtering bypass.
Does exploitation require authentication or user interaction?
No. The supplied vector indicates network-accessible exploitation with low attack complexity, no privileges, and no user interaction required.
What does an attacker need to do to exploit this issue?
An attacker uses URL encoding to bypass extension validation and request sensitive theme files. The reported impact is limited to reading theme templates and metadata.
How can I remediate the vulnerability?
Upgrade Ghost to version 6.20.0 or later. The provided information does not identify a temporary mitigation for deployments that cannot yet be upgraded.