File Overwrite Vulnerability in Ghost CMS by TryGhost
CVE-2026-70592
5.5MEDIUM
What is CVE-2026-70592?
Ghost, a Node.js content management system, is susceptible to a file overwrite vulnerability that allows an Administrator-level user to remotely overwrite certain files on the filesystem via the database backup filename. This vulnerability arises due to the failure of the database export endpoint to adequately validate path separators in user-supplied filenames. As a result, this could lead to serious integrity and availability issues for affected installations. The issue has been resolved in version 6.54.1.
Affected Version(s)
Ghost >= 1.20.1, < 6.54.1
