THREAT OPS › Threat News › [GHSA] GHSA-cj62-hvv2-2q5h (medium) — Ghost: Database Backup Path Traversal
[GHSA] GHSA-cj62-hvv2-2q5h (medium) — Ghost: Database Backup Path Traversal
GHSA-cj62-hvv2-2q5h Severity: medium CVE: CVE-2026-70592
Ghost: Database Backup Path Traversal
### Impact
An Administrator-level user could remotely overwrite certain files on the filesystem leading to integrity and availability issues.
### Vulnerable versions
This vulnerability is present in Ghost from 1.20.1 up to v6.54.0.
### Patches
v6.54.1 contains a fix for this issue.
### How to upd
Indicators of compromise
- CVE-2026-70592cve
- https://hub.docker.com/_/ghosturl
- https://docs.ghost.org/install/docker#updating-ghosturl
- https://docs.ghost.org/updateurl
- security@ghost.orgemail
Original source: https://github.com/advisories/GHSA-cj62-hvv2-2q5h