THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-cjc9-q5gf-327p (medium) — Ghost: Theme Upload Path Traversal

[GHSA] GHSA-cjc9-q5gf-327p (medium) — Ghost: Theme Upload Path Traversal

highgithub_advisoriesPublished 2026-08-04

GHSA-cjc9-q5gf-327p Severity: medium CVE: CVE-2026-70593

Ghost: Theme Upload Path Traversal

### Impact

A vulnerability in custom themes allowed a staff user to write files outside of the uploads directory. This could be used to alter the behavior of the installation.

### Vulnerable versions

This vulnerability is present in Ghost from v0.10.0 up to v6.54.0.

### Patches

v6.54.1 contains a fix

Indicators of compromise

Original source: https://github.com/advisories/GHSA-cjc9-q5gf-327p