AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-70592

MEDIUM · CVSS 5.5 EPSS 0.30% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-04 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

A vulnerability exists in the Ghost Node.js content management system, allowing an Administrator-level user to remotely overwrite files on the filesystem via an improperly validated database backup filename, which could compromise data integrity and availability. Organizations using affected versions from 1.20.1 to 6.54.1 should prioritize updating to version 6.54.1 to mitigate this risk. This issue is particularly relevant for system administrators and security teams managing Ghost installations.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-70592
Severity
MEDIUM
CVSS
5.5
EPSS
0.30%

Original NVD Description

Ghost is a Node.js content management system. From 1.20.1 until 6.54.1, an Administrator-level user could remotely overwrite certain files on the filesystem through the database backup filename, leading to integrity and availability issues. The database export endpoint failed to reject path separators in the caller-supplied filename. This issue is fixed in version 6.54.1.