File Extension Filtering Bypass in Ghost by TryGhost
CVE-2026-103276
6.9MEDIUM
What is CVE-2026-103276?
Ghost versions prior to 6.20.0 are susceptible to a file extension filtering bypass vulnerability. This issue allows unauthenticated attackers to exploit URL encoding techniques, enabling them to bypass the standard extension validation checks. As a result, attackers can gain unauthorized access to sensitive theme templates and metadata, potentially leading to further exploitation or exposure of confidential information within the application.
Affected Version(s)
Ghost 0 < 6.20.0
Ghost 6.20.0
