Path Traversal Vulnerability in Ghost Product by TryGhost
CVE-2026-103290
5.1MEDIUM
What is CVE-2026-103290?
Ghost versions from 6.14.0 to prior 6.27.0 are susceptible to a path traversal vulnerability within the ImageSize service. This flaw arises due to inadequate validation of user-provided file paths, potentially enabling authenticated staff users to manipulate access to local files situated outside of designated storage directories on the server.
Affected Version(s)
Ghost 6.14.0 < 6.27.0
Ghost 6.27.0
