CVE-2026-105683: Ghost: Path Traversal Vulnerability in Ghost ImageSize Service
Ghost is a Node.js content management system. From 6.14.0 until 6.27.0, an input validation issue may have allowed staff users to access local files outside the intended data storage directories on the server. This issue is fixed in version 6.27.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ghostto a version that resolves this vulnerability.Fixed in 6.27.0
Event History
Frequently Asked Questions
Which deployments are affected?
Ghost deployments running versions from 6.14.0 up to, but not including, 6.27.0 are affected. Version 6.27.0 fixes the issue.
What level of access does an attacker need?
An attacker needs staff-user access to the Ghost instance. The issue may allow such a user to access local files outside the intended server data storage directories.
What should be done if the instance is vulnerable?
Upgrade Ghost to version 6.27.0. The provided information does not identify a separate workaround for deployments that cannot be upgraded immediately.