CVE-2026-103276
6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Summary
Ghost versions before 6.20.0 contain a file extension filtering bypass vulnerability that allows unauthenticated attackers to read theme templates and metadata. Attackers can use URL encoding to bypass extension validation and access sensitive theme files.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| TryGhost | Ghost | 0 < 6.20.0 | affected |
| TryGhost | Ghost | 6.20.0 | unaffected |
Weaknesses
- CWE-173: Improper Handling of Alternate Encoding
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: yes
- Technical Impact: partial
References
- https://github.com/TryGhost/Ghost/security/advisories/GHSA-6v8p-3jx9-8chr
- https://www.vulncheck.com/advisories/ghost-before-6.20.0-file-read-via-url-encoding-bypass
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.