CVE-2026-103276: Tryghost Ghost
Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.
Ghost versions before 6.20.0 contain a file extension filtering bypass vulnerability that allows unauthenticated attackers to read theme templates and metadata. Attackers can use URL encoding to bypass extension validation and access sensitive theme files.
Affected products
- Tryghost Ghost: before 6.20.0 (fixed in 6.20.0)
Published 2026-10-01. Last modified 2026-10-01.