CVE-2026-105683lowCWE-35

CVE-2026-105683: low-severity vulnerability in TryGhost Ghost

Ghost: Path Traversal Vulnerability in Ghost ImageSize Service

Published · Updated

8Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 3.8epss 0.3%
exploitation probability
0.3%top 78% of all CVEs
observed exploitation
nono source reports it
Ghost is a Node.js content management system. From 6.14.0 until 6.27.0, an input validation issue may have allowed staff users to access local files outside the intended data storage directories on the server. This issue is fixed in version 6.27.0.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:L
Affected products
TryGhost · Ghost