Sceawere
Vulnerability Detail
CVE-2026-105683UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Ghost Arbitrary Local File Access
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 3.8
- Creation Date
- 1h ago
- Vendor
- TryGhost
- Product
- Ghost
- Attack Type
- CWE-35: Path Traversal: '.../...//'
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Ghost is a Node.js content management system. From 6.14.0 until 6.27.0, an input validation issue may have allowed staff users to access local files outside the intended data storage directories on the server. This issue is fixed in version 6.27.0.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "3.8",
"pubDate": "2026-10-05T20:17:17.123Z",
"pubdate": "2026-10-05T20:17:17.123Z",
"executiveSummary": "A critical input validation vulnerability exists within the Ghost content management system, potentially allowing authenticated staff users to bypass directory restrictions and access arbitrary files located outside of designated data storage directories on the host server.\nThe vulnerability is classified as an input validation flaw that compromises the integrity of file system access controls. By exploiting this weakness, a malicious or compromised staff account can retrieve sensitive server-side files, leading to potential information disclosure.\nThe scope of this issue affects Ghost versions 6.14.0 through 6.27.0. Successful exploitation requires an attacker to possess existing staff-level privileges within the application. The impact is significant, as it permits unauthorized read access to the underlying server environment, which could expose configuration files, credentials, or other system assets. Organizations utilizing affected versions are at risk of lateral movement or further exploitation if sensitive system information is successfully exfiltrated.",
"technicalDetails": "The vulnerability stems from improper neutralization of user-supplied input when interacting with the server's file system interface. Within Ghost versions 6.14.0 to 6.27.0, the application fails to adequately sanitize or validate path parameters before performing file read operations.\nThe root cause resides in the application's internal file handling logic, which lacks robust path traversal protections. When a staff user initiates specific requests involving file retrieval or processing, the system does not enforce strict boundaries, allowing the input to contain traversal sequences such as '../'. Consequently, the system resolves these malicious paths against the root of the server rather than the intended sandboxed directory.\nThe attack flow begins with an authenticated staff user sending a crafted request to the Ghost instance containing path manipulation payloads. Because the application logic fails to verify that the target path remains within the predefined storage boundaries, the underlying Node.js process attempts to access the requested file location on the host file system. Since the application process inherently possesses the permissions of the user running the Ghost service, it effectively bypasses application-level directory restrictions.\nThis vulnerability is limited to authenticated staff users, as the entry point for the exploit is exposed through functional modules accessible only to those with appropriate administrative or staff permissions. The exploitation does not necessarily require direct network exposure beyond the standard web access provided to authorized staff members, but the post-exploitation impact includes the ability to read sensitive files, such as environment configuration, database credentials, or system-level files accessible to the Ghost service process. This facilitates reconnaissance, potentially leading to a total compromise of the server or the underlying infrastructure."
}