In-app reader
An Administrator-level user could remotely overwrite certain files on the filesystem leading to integrity and availability issues.
This vulnerability is present in Ghost from 1.20.1 up to v6.54.0.
v6.54.1 contains a fix for this issue.
For self-hosters using Docker, find Docker's official Ghost image here. Updating a Docker-based Ghost instance is documented here.
If your Ghost is a Ghost-CLI install see our documentation on updating it to the latest version here.
If upgrading immediately is not possible, set disableJSBackups to "true" by running:
$ ghost config set disableJSBackups true
$ ghost restart
Discussion
Sign in to join the discussion.
Keep reading
Optional: create a free account to save items, track programs, and sync across web + app. Reading stays free.