THREAT OPS › Threat News › [GHSA] GHSA-cjc9-q5gf-327p (medium) — Ghost: Theme Upload Path Traversal
[GHSA] GHSA-cjc9-q5gf-327p (medium) — Ghost: Theme Upload Path Traversal
GHSA-cjc9-q5gf-327p Severity: medium CVE: CVE-2026-70593
Ghost: Theme Upload Path Traversal
### Impact
A vulnerability in custom themes allowed a staff user to write files outside of the uploads directory. This could be used to alter the behavior of the installation.
### Vulnerable versions
This vulnerability is present in Ghost from v0.10.0 up to v6.54.0.
### Patches
v6.54.1 contains a fix
Indicators of compromise
- CVE-2026-70593cve
- https://hub.docker.com/_/ghosturl
- https://docs.ghost.org/install/docker#updating-ghosturl
- https://docs.ghost.org/updateurl
- security@ghost.orgemail
Original source: https://github.com/advisories/GHSA-cjc9-q5gf-327p