AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-70593

MEDIUM · CVSS 6.6 EPSS 0.29% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-04 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

A vulnerability in Ghost, a Node.js content management system, allows staff users to exploit custom themes to write files outside the designated uploads directory, potentially altering the installation's behavior. This issue affects versions from 0.10.0 to 6.54.1 and is addressed in version 6.54.1. Organizations using affected versions should prioritize updating to the latest release to mitigate the risk of unauthorized file manipulation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-70593
Severity
MEDIUM
CVSS
6.6
EPSS
0.29%

Original NVD Description

Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a vulnerability in custom themes allowed a staff user to write files outside of the uploads directory. This could be used to alter the behavior of the installation through custom theme upload path traversal in LocalStorageBase and theme storage name handling. This issue is fixed in version 6.54.1.