Node.js Content Management System Vulnerability in Ghost Affecting Multiple Versions
CVE-2026-70593

6.6MEDIUM

Key Information:

Vendor

Tryghost

Status
Vendor
CVE Published:
4 August 2026

What is CVE-2026-70593?

A vulnerability in Ghost CMS allows staff users to leverage malicious custom themes to write files outside the designated uploads directory. This issue originates from improper handling of theme upload paths and LocalStorageBase, which could potentially compromise the integrity of the installation. Users are encouraged to update to version 6.54.1 or later, which addresses this flaw.

Affected Version(s)

Ghost >= 0.10.0, < 6.54.1

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.