← Vulnerability feed

Vulnerability record · CVE-2023-40028 · published 15 August 2023

CVE-2023-40028: Ghost CMS authenticated symlink upload allows arbitrary file read

Ghost · Ghost

Ghost versions before 5.59.1 let authenticated users upload files that are symlinks, which the CMS then follows. This enables reading any file on the host operating system, exposing configuration, credentials and other sensitive data. The vendor fixed the issue in 5.59.1 and states there are no workarounds.

6.5 CVSS 3.1 Medium EPSS 69% · top 0.7% CWE-22 · Path traversalCWE-59 · Link following
6.5CVSS 3.1 base score
69%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Ghost is an open source content management system. Versions prior to 5.59.1 are subject to a vulnerability which allows authenticated users to upload files that are symlinks. This can be exploited to perform an arbitrary file read of any file on the host operating system. Site administrators can check for exploitation of this issue by looking for unknown symlinks within Ghost's `content/` folder. Version 5.59.1 contains a fix for this issue. All users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityThe flaw allows authenticated arbitrary file read with a high EPSS score, though it requires a valid account and is not known to be actively exploited.

What it is

Ghost versions before 5.59.1 let authenticated users upload files that are symlinks, which the CMS then follows. This enables reading any file on the host operating system, exposing configuration, credentials and other sensitive data. The vendor fixed the issue in 5.59.1 and states there are no workarounds.

Impact

An attacker with a valid account gains read access to arbitrary files on the server, including secrets and configuration that can support further compromise. There is no write or code execution impact described in the record.

Attack surface

The flaw is reachable over the network through Ghost's file upload functionality, requiring a low-privileged authenticated account and no user interaction. The CVSS vector confirms network access, low privileges and no UI requirement.

Exploitation

CVE-2023-40028 is not listed in CISA KEV and no ransomware use is documented, but EPSS is high at roughly 0.69 (99th percentile), indicating elevated likelihood of exploitation activity. References only include the patch commit and vendor advisory, with no public exploit tags.

What to do

  • Upgrade Ghost to version 5.59.1 or later, which contains the fix.
  • If immediate upgrade is not possible, restrict who can upload files and review accounts with upload permissions, since no workaround exists.
  • Audit Ghost's content/ folder for unexpected symlinks and remove any found.
  • Run Ghost with least-privilege filesystem permissions so a file read cannot reach sensitive host files.
  • Monitor vendor advisory GHSA-9c9v-w225-v5rg for updates.

Detection

  • Search Ghost's content/ directory for symlinks that are not expected, as the vendor recommends.
  • Alert on file uploads that resolve to symlinks or point outside the content directory.
  • Review Ghost logs for upload activity from low-privileged or unusual accounts.
  • Monitor for reads of sensitive files such as configuration or credential files by the Ghost process.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-40028 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-29053Ghost injection vulnerabilityGhost is a Node.js content management system. From version 0.7.2 to 6.19.0, specifically crafted malicious themes can execute arbitrary code on the s…EPSS 4.8%9.8CVE-2022-28397Ghost unrestricted file upload vulnerabilityAn arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file. …EPSS 3.5%9.8CVE-2022-27139Ghost unrestricted file upload vulnerabilityAn arbitrary file upload vulnerability in the file upload module of Ghost v4.39.0 allows attackers to execute arbitrary code via a crafted SVG file. …EPSS 4.0%9.1CVE-2024-34451Ghost vulnerabilityGhost through 5.85.1 allows remote attackers to bypass an authentication rate-limit protection mechanism by using many X-Forwarded-For headers with d…EPSS 0.77%9.0CVE-2024-23724Ghost cross-site scripting vulnerabilityGhost through 5.76.0 allows stored XSS, and resultant privilege escalation in which a contributor can take over any account, via an SVG profile pictu…EPSS 3.5%8.8CVE-2026-29784Ghost cross-site request forgery vulnerabilityGhost is a Node.js content management system. From version 5.101.6 to 6.19.2, incomplete CSRF protections around /session/verify made it possible to …EPSS 0.19%8.8CVE-2024-34448Ghost injection vulnerabilityGhost before 5.82.0 allows CSV Injection during a member CSV export.EPSS 0.73%8.1CVE-2026-22594Ghost improper authentication vulnerabilityGhost is a Node.js content management system. In versions 5.105.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's 2FA mechanism …EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2023-40028), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.