CVE-2022-27139 is an arbitrary file upload vulnerability in the file upload module of Ghost v4.39.0, allowing attackers to execute arbitrary code via crafted SVG files. This vulnerability carries a critical CVSS score of 9.8, indicating a network-based attack with low complexity that can lead to high impact on confidentiality, integrity, and availability. Despite the high severity, the vendor notes that SVG uploads are restricted to trusted authenticated users and do not inherently lead to server-side remote code execution. Currently, there is no public exploit intelligence, such as Metasploit or ExploitDB modules, and the vulnerability has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.39.0CPE matchmatch criteria | cpe:2.3:a:ghost:ghost:4.39.0:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.