Low severity3.8NVD Advisory· Published Oct 1, 2026
CVE-2026-103290
CVE-2026-103290
Description
Ghost versions 6.14.0 through versions prior to 6.27.0 contain a path traversal vulnerability in the ImageSize service. Insufficient input validation of user-supplied file paths may allow authenticated staff users to access local files outside the intended data storage directories on the server.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.