github.com
https://github.com/TryGhost/Ghost CVE-2026-70592
MEDIUM
Ghost: Database Backup Path Traversal
Record summary
CVE-2026-70592 has a selected CVSS score of 5.5 (medium).
Description
Ghost is a Node.js content management system. From 1.20.1 until 6.54.1, an Administrator-level user could remotely overwrite certain files on the filesystem through the database backup filename, leading to integrity and availability issues. The database export endpoint failed to reject path separators in the caller-supplied filename. This issue is fixed in version 6.54.1.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 5, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | >= 1.20.1, < 6.54.1 | affected | |
ghostBrowse npm / ghost | GitHub Advisory | 1.20.1 to < 6.54.1 · Fixed in 6.54.1 | affected |
References
4github.com
https://github.com/TryGhost/Ghost/commit/f466c300191a609ed36c8d7c5d1e33ccd440786b github.com
https://github.com/TryGhost/Ghost/releases/tag/v6.54.1 github.comConfirmation
https://github.com/TryGhost/Ghost/security/advisories/GHSA-cj62-hvv2-2q5h