{"id":"BIT-ghost-2022-27139","details":"An arbitrary file upload vulnerability in the file upload module of Ghost v4.39.0 allows attackers to execute arbitrary code via a crafted SVG file. NOTE: Vendor states that as outlined in Ghost's security documentation, upload of SVGs is only possible by trusted authenticated users. The uploading of SVG files to Ghost does not represent a remote code execution vulnerability. SVGs are not executable on the server, and may only execute javascript in a client's browser - this is expected and intentional functionality","aliases":["CVE-2022-27139","GHSA-fvc6-qjp7-m4g4"],"modified":"2026-09-08T08:47:32.546161438Z","published":"2024-03-06T10:54:02.089Z","database_specific":{"severity":"Critical","cpes":["cpe:2.3:a:ghost:ghost:4.39.0:*:*:*:*:node.js:*:*","cpe:2.3:a:ghost:ghost:*:*:*:*:*:node.js:*:*"]},"references":[{"type":"WEB","url":"http://ghost.org/docs/security/#privilege-escalation-attacks"},{"type":"ADVISORY","url":"https://youtu.be/FCqWEvir2wE"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-27139"}],"affected":[{"package":{"name":"ghost","ecosystem":"Bitnami","purl":"pkg:bitnami/ghost"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.39.0"},{"fixed":"4.39.1"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/ghost/BIT-ghost-2022-27139.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}],"schema_version":"1.9.0"}