Product
Ghost CMS versions prior to 5.59.1 are vulnerable to an authenticated arbitrary file read, exploitable through malicious symbolic link uploads via the administrative API.