CVE-2026-70593
published 2026-08-04CVE-2026-70593: Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a vulnerability in custom themes allowed a staff user to write files outside of the…
PriorityP336medium6.6CVSS 3.1
AVNACHPRHUINSCCNIHAL
EPSS
0.41%
33.2th percentile
Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a vulnerability in custom themes allowed a staff user to write files outside of the uploads directory. This could be used to alter the behavior of the installation through custom theme upload path traversal in LocalStorageBase and theme storage name handling. This issue is fixed in version 6.54.1.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ghost | ghost | >= 0.10.0 < 6.54.1 | 6.54.1 |
| tryghost | ghost | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
TryGhost up to 6.54.0 LocalStorageBase path traversal
vuldb·2026-08-05·CVSS 6.6
CVE-2026-70593 [MEDIUM] TryGhost up to 6.54.0 LocalStorageBase path traversal
A vulnerability classified as critical has been found in TryGhost Ghost up to 6.54.0. This vulnerability affects unknown code of the component LocalStorageBase. This manipulation causes path traversal.
This vulnerability appears as CVE-2026-70593. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
GHSA
Ghost: Theme Upload Path Traversal
ghsa·2026-08-04
CVE-2026-70593 [MEDIUM] CWE-22 Ghost: Theme Upload Path Traversal
Ghost: Theme Upload Path Traversal
### Impact
A vulnerability in custom themes allowed a staff user to write files outside of the uploads directory. This could be used to alter the behavior of the installation.
### Vulnerable versions
This vulnerability is present in Ghost from v0.10.0 up to v6.54.0.
### Patches
v6.54.1 contains a fix for this issue.
### How to update
For self-hosters using Docker, find [Docker's official Ghost image here](https://hub.docker.com/_/ghost). Updating a Docker-based Ghost instance [is documented here](https://docs.ghost.org/install/docker#updating-ghost).
If your Ghost is a Ghost-CLI install see our documentation on [updating it to the latest version here](https://docs.ghost.org/update).
### References
Ghost thanks Stephen Sims, Off By One Security
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-04
Published