CVE-2023-40028 affects Ghost, the open source content management system. In Ghost versions prior to 5.59.1, authenticated users can upload files that are symbolic links. Because these symlinks can reference files outside the intended content directory, the issue can be abused to read arbitrary files from the underlying host operating system. The vulnerable condition is tied to insufficient validation or restriction of uploaded files, specifically allowing symlink objects to be accepted within Ghost's content handling workflow. Successful exploitation results in arbitrary file read from the server filesystem.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
content/ folder for unexpected symlinks, and limit filesystem permissions available to the Ghost process so that sensitive host files are not readable where possible. These measures do not replace patching.Patch, then assume compromise.
content/ directory for unknown or suspicious symbolic links to identify possible prior exploitation. Remove any unauthorized symlinks and assess whether sensitive files may have been exposed. Rotate any credentials or secrets that may have been readable by the Ghost process if compromise is suspected.9 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository contains a single Python exploit (exploit.py) plus a short README. The exploit targets CVE-2023-40028 in Ghost CMS and performs an authenticated attack: it logs into the Ghost admin session endpoint (/ghost/api/admin/session) using provided credentials, then abuses the admin database import endpoint (/ghost/api/v3/admin/db) by uploading a crafted ZIP created in-memory. The ZIP contains a ZipInfo entry for a path under content/images/ with Unix/symlink-like attributes set; the ZIP entry data is the attacker-supplied file path to read (e.g., /etc/passwd). After upload, the script requests the resulting URL (/content/images/<rand>.png) and prints the HTTP response body, effectively providing arbitrary file read from the server. The script is interactive (loops until 'exit'/'quit'), generating a random 5-letter filename each iteration. No additional tooling, persistence, or RCE payloads are included—its primary capability is file disclosure over HTTP.
This repository contains a working exploit for CVE-2023-40028, a vulnerability in Ghost CMS (prior to version 5.59.1) that allows authenticated users to read arbitrary files from the server. The exploit is implemented in Python (exp.py) and requires valid Ghost admin credentials. The script authenticates to the Ghost admin API, creates a symlink to a target file, packages it in a zip, uploads it via the API, and then retrieves the file contents by accessing the symlinked file through a public URL. The exploit demonstrates the vulnerability by allowing the attacker to specify any file path, and automates the process of payload creation, upload, and retrieval. The README provides usage instructions and context about the vulnerability. The main endpoints targeted are the Ghost admin API for authentication and file upload, and the public images directory for file retrieval. The exploit is operational and demonstrates a real-world attack scenario.
This repository contains a Python exploit (exploit.py) and a README.md for CVE-2023-40028, a vulnerability in Ghost CMS versions prior to 5.59.1. The exploit targets the Ghost CMS admin API, requiring valid credentials to authenticate. It abuses the import mechanism by uploading a ZIP file containing a symlink to an arbitrary file on the server. Once uploaded, the attacker can access the contents of the targeted file via the web server. The exploit is interactive, prompting the user for file paths to read from the server. The code is operational and demonstrates the full attack chain, including authentication, payload creation, upload, and file retrieval. The main endpoints targeted are the Ghost CMS admin session and database import APIs. The exploit is not part of a framework and is implemented in Python.
This repository provides a proof-of-concept exploit for CVE-2023-40028, a Local File Inclusion (LFI) vulnerability in Ghost CMS versions prior to 5.59.1. The exploit is implemented in a single Python script (exploit.py), which authenticates to the Ghost CMS admin API using provided credentials, creates a zip archive containing a symlink to a sensitive file (default: /etc/passwd), uploads this archive via the API, and then retrieves the contents of the symlinked file through the public images endpoint. The exploit demonstrates the ability for authenticated users to read arbitrary files from the server filesystem by abusing improper file upload handling. The repository also includes a README.md with detailed usage instructions and vulnerability background, and a standard GPL license file. No hardcoded endpoints are present; the script is configurable via command-line arguments. The exploit is a functional proof-of-concept and does not include weaponized or automated post-exploitation features.
This repository contains a Python exploit script (exploit.py) targeting CVE-2023-40028, a vulnerability in Ghost CMS that allows arbitrary file read via symbolic link abuse in the image upload functionality. The exploit requires valid admin credentials for the Ghost admin API. The script works by creating a symlink to a user-specified file, packaging it into a ZIP archive, and uploading it through the Ghost admin API. The file is then accessible via a public image URL, allowing the attacker to read its contents. The script also includes cleanup routines to remove traces after execution. The repository includes a README with usage instructions and a LICENSE file. The main entry point is exploit.py, written in Python, and the attack vector is network-based, targeting the Ghost CMS admin API endpoints.
This repository provides a Python proof-of-concept exploit for CVE-2023-40028, a vulnerability in Ghost CMS (prior to version 5.59.1) that allows authenticated users to read arbitrary files from the server. The exploit works by uploading a ZIP archive containing a symlink to the desired file via the Ghost CMS admin API. The symlink is then accessed through the public images endpoint, allowing the attacker to read the contents of any file on the server that the Ghost process can access. The exploit requires valid authentication (either via username/password or a session cookie). The repository consists of a single exploit script ('ghost_fileread.py') and a README with detailed usage instructions and background on the vulnerability. The main attack vector is network-based, targeting the Ghost CMS admin API and images endpoint. Notable endpoints include '/ghost/api/v3/admin/db' for ZIP upload, '/content/images/{symlinked_filename}' for file retrieval, and '/ghost/api/v3/admin/session/' for authentication. The exploit is a functional proof-of-concept and does not include weaponized or automated post-exploitation features.
This repository contains a proof-of-concept exploit for CVE-2023-40028, a symlink upload vulnerability in Ghost CMS versions prior to 5.59.1. The exploit consists of a single Python script ('exploit.py') and a README file. The script automates the process of authenticating to a target Ghost CMS instance using provided credentials, creating a symlink to an arbitrary file, packaging it into a zip file, and uploading it via the Ghost CMS admin API. After upload, the script accesses the symlinked file through the public images directory, allowing the attacker to read arbitrary files from the server. The exploit requires valid user credentials and network access to the Ghost CMS admin interface. The code is a functional proof-of-concept and does not include advanced features such as payload customization or post-exploitation modules.
This repository contains a Bash script exploit for CVE-2023-40028, a vulnerability in Ghost CMS that allows authenticated attackers to read arbitrary files from the server. The exploit automates the process of logging into the Ghost CMS admin API, generating a malicious ZIP file with a symlink to a user-specified file, uploading it via the database import endpoint, and then retrieving the file's contents through the public images directory. The script is interactive, prompting the user for file paths to read, and cleans up temporary files after each operation. The exploit requires valid admin credentials for the target Ghost CMS instance and network access to the admin API. The repository also includes a detailed README.md explaining the vulnerability, usage instructions, and workflow. The main attack vector is network-based, targeting the Ghost CMS admin API endpoints. The exploit is operational, providing a working file read capability but not weaponized for mass exploitation.
This repository contains a proof-of-concept (POC) exploit for CVE-2023-40028, a vulnerability in Ghost CMS versions prior to 5.59.1 that allows authenticated users to upload symlinks, leading to arbitrary file read on the server. The main exploit is a Bash script (CVE-2023-40028.sh) that prompts the user for Ghost admin credentials and the file path to read. It creates a symlink to the target file, packages it in a zip archive, and uploads it to the Ghost admin API using the authenticated session. The script then retrieves the contents of the symlinked file via the public images directory. The exploit requires network access to the Ghost admin API and valid credentials. The repository also includes a README.md with detailed vulnerability and mitigation information. The exploit is a functional POC and does not include weaponized or automated payloads beyond file reading.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.