Vulnerability record · CVE-2023-40028 · published 15 August 2023
CVE-2023-40028: Ghost CMS authenticated symlink upload allows arbitrary file read
Ghost · Ghost
Ghost versions before 5.59.1 let authenticated users upload files that are symlinks, which the CMS then follows. This enables reading any file on the host operating system, exposing configuration, credentials and other sensitive data. The vendor fixed the issue in 5.59.1 and states there are no workarounds.
Description
Ghost is an open source content management system. Versions prior to 5.59.1 are subject to a vulnerability which allows authenticated users to upload files that are symlinks. This can be exploited to perform an arbitrary file read of any file on the host operating system. Site administrators can check for exploitation of this issue by looking for unknown symlinks within Ghost's `content/` folder. Version 5.59.1 contains a fix for this issue. All users are advised to upgrade. There are no known workarounds for this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityThe flaw allows authenticated arbitrary file read with a high EPSS score, though it requires a valid account and is not known to be actively exploited.
What it is
Ghost versions before 5.59.1 let authenticated users upload files that are symlinks, which the CMS then follows. This enables reading any file on the host operating system, exposing configuration, credentials and other sensitive data. The vendor fixed the issue in 5.59.1 and states there are no workarounds.
Impact
An attacker with a valid account gains read access to arbitrary files on the server, including secrets and configuration that can support further compromise. There is no write or code execution impact described in the record.
Attack surface
The flaw is reachable over the network through Ghost's file upload functionality, requiring a low-privileged authenticated account and no user interaction. The CVSS vector confirms network access, low privileges and no UI requirement.
Exploitation
CVE-2023-40028 is not listed in CISA KEV and no ransomware use is documented, but EPSS is high at roughly 0.69 (99th percentile), indicating elevated likelihood of exploitation activity. References only include the patch commit and vendor advisory, with no public exploit tags.
What to do
- Upgrade Ghost to version 5.59.1 or later, which contains the fix.
- If immediate upgrade is not possible, restrict who can upload files and review accounts with upload permissions, since no workaround exists.
- Audit Ghost's content/ folder for unexpected symlinks and remove any found.
- Run Ghost with least-privilege filesystem permissions so a file read cannot reach sensitive host files.
- Monitor vendor advisory GHSA-9c9v-w225-v5rg for updates.
Detection
- Search Ghost's content/ directory for symlinks that are not expected, as the vendor recommends.
- Alert on file uploads that resolve to symlinks or point outside the content directory.
- Review Ghost logs for upload activity from low-privileged or unusual accounts.
- Monitor for reads of sensitive files such as configuration or credential files by the Ghost process.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-40028 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-40028), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.