CVE-2026-103276 PUBLISHED

Ghost before 6.20.0 File Read via URL Encoding Bypass

Assigner: VulnCheck
Reserved: 30.09.2026 Published: 01.10.2026 Updated: 01.10.2026

Ghost versions before 6.20.0 contain a file extension filtering bypass vulnerability that allows unauthenticated attackers to read theme templates and metadata. Attackers can use URL encoding to bypass extension validation and access sensitive theme files.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor TryGhost
Product Ghost
Versions Default: unaffected
  • affected from 0 to 6.20.0 (excl.)
  • Version 6.20.0 is unaffected

References

Problem Types

  • Improper Handling of Alternate Encoding CWE