{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aghostghostnode.js/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ghost:ghost:*:*:*:*:*:node.js:*:*"],"_cs_cves":[{"cvss":4.9,"id":"CVE-2023-40028"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Ghost CMS (\u003c 5.59.1)"],"_cs_severities":["medium"],"_cs_tags":["ghost-cms","arbitrary-file-read","web-application","cve-2023-40028","vulnerability"],"_cs_type":"threat","_cs_vendors":["Ghost"],"content_html":"\u003cp\u003eCVE-2023-40028 is an arbitrary file read vulnerability affecting Ghost CMS versions prior to 5.59.1. The vulnerability arises from improper validation during file upload, allowing an authenticated attacker with administrative privileges to upload files as symbolic links. By manipulating these links, an attacker can bypass directory restrictions and access arbitrary files on the host operating system. This vulnerability has been categorized with a CVSS score of 6.5 (Medium). Proof-of-concept exploit code has been published publicly, demonstrating that the attack chain leverages the \u003ccode\u003e/ghost/api/v3/admin/session/\u003c/code\u003e endpoint for initial authentication, followed by the malicious upload process. Defenders should prioritize patching Ghost CMS to version 5.59.1 or later.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthorized access to sensitive files residing on the host server. Depending on the server configuration and file permissions, this could lead to the exposure of configuration files, environment variables, or other sensitive system data. Organizations utilizing versions of Ghost CMS older than 5.59.1 are at risk, particularly if administrative accounts are compromised.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch Ghost CMS to version 5.59.1 or later immediately as the primary mitigation.\u003c/li\u003e\n\u003cli\u003eAudit the \u003ccode\u003econtent/\u003c/code\u003e directory of Ghost CMS installations to identify and remove any unauthorized symbolic links.\u003c/li\u003e\n\u003cli\u003eMonitor administrative authentication logs for suspicious activity, particularly around the \u003ccode\u003e/ghost/api/v3/admin/session/\u003c/code\u003e endpoint, to detect account misuse.\u003c/li\u003e\n\u003cli\u003eImplement strict ingress filtering and restrict administrative access to trusted management IP ranges to limit the risk of exploitation by unauthorized actors.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-07T22:43:15Z","date_published":"2026-09-07T22:43:15Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2023-40028-ghost-cms/","summary":"Ghost CMS versions prior to 5.59.1 are vulnerable to an authenticated arbitrary file read, exploitable through malicious symbolic link uploads via the administrative API.","title":"Arbitrary File Read in Ghost CMS via CVE-2023-40028","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2023-40028-ghost-cms/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:ghost:ghost:*:*:*:*:*:node.js:*:*","version":"https://jsonfeed.org/version/1.1"}