Junglewise Threat Intelligence

CVE-2023-32235: Ghost path traversal in theme assets

CVE-2023-32235 · Severity: low · CVSS 3.1 · Published 2023-05-05

Technologies: ghost (npm). Vendors: Ghost, npm.

Executive brief

Ghost is a popular open-source blogging and publishing platform. A path traversal vulnerability allows unauthenticated remote attackers to read arbitrary files from the active theme folder by using encoded directory traversal sequences in asset URLs, potentially exposing theme configuration files, templates, and other sensitive theme data.

Technical details

The vulnerability is a path traversal flaw (CWE-22) in Ghost's static theme middleware (`frontend/web/middleware/static-theme.js`). Attackers can bypass directory restrictions by using URL-encoded traversal sequences (e.g., %2F for / and %2E for .) in requests to `/assets/built/../../../` to access files outside the intended assets directory within the active theme folder. The vulnerability is network-accessible and requires no authentication or user interaction. An attacker can read arbitrary files within the active theme's folder, potentially exposing sensitive configuration and template data. The issue was fixed in Ghost 5.42.1; all prior versions are affected.

Affected products

  • Ghost Ghost before 5.42.1

Timeline

  • 2023-05-05: disclosed
  • 2023-05-05: patched: Fixed in version 5.42.1

References

Related threats