GHSA-v575-g66p-vj84MediumCVSS 5.3

Ghost versions before 6.20.0 contain a file extension filtering bypass vulnerability that allows...

Published
October 1, 2026
Last Modified
October 1, 2026

🔗 CVE IDs covered (1)

📋 Description

Ghost versions before 6.20.0 contain a file extension filtering bypass vulnerability that allows unauthenticated attackers to read theme templates and metadata. Attackers can use URL encoding to bypass extension validation and access sensitive theme files.

🔗 References (4)