ghost is vulnerable to Insecure Inherited Permissions
85
High Risk
Affected versions of this package are vulnerable to Remote Code Execution (RCE) due to improper handling of file permissions for uploaded files. Previously, uploaded files retained their original permissions, potentially leaving them executable and creating a security risk. The issue has been addressed by enforcing 0644 permissions on all files uploaded via the Ghost importer, ensuring they are non-executable and significantly reducing the risk of exploitation.
You are affected if you are using a version that falls within the vulnerable range.
ghost is vulnerable to Insecure Inherited Permissions in versions 0.0.1 - 5.104.0.
Upgrade the ghost library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant