Description
Ghost from 1.20.0 before 6.64.0 contains a path traversal vulnerability in theme translation file loading that allows authenticated administrators to read JSON files outside the active theme directory. Attackers can manipulate the locale setting to load JSON files elsewhere on the server, exposing server configuration secrets.
Published: 2026-10-02
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Confidentiality Compromise
Action: Immediate Patch
AI Analysis

Impact

Ghost versions 1.20.0 through 6.63.99 contain a path traversal flaw in theme translation file loading. The flaw allows an authenticated administrator to specify an arbitrary locale value, causing the system to load JSON files outside the active theme directory. By reading these files an attacker can obtain server configuration secrets and other sensitive data. The weakness is a classic Directory Traversal (CWE-22).

Affected Systems

The affected product is Ghost from TryGhost. Any installation of Ghost from version 1.20.0 up to, but not including, 6.64.0 is vulnerable. Upgrading beyond 6.64.0 eliminates the flaw.

Risk and Exploitability

The CVSS score is 6.9, indicating a high severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. The attack requires authenticated administrator privileges and manipulation of the locale setting; it does not rely on network exposure or remote code execution. An attacker controlling an administrator session can read arbitrary files, compromising confidentiality of server configuration and potentially other secrets.

Generated by OpenCVE AI on October 2, 2026 at 13:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Ghost to version 6.64.0 or later, which removes the path traversal vulnerability.
  • Restrict administrator privileges to trusted users and enforce least privilege so that only those who need to modify locale have admin access.
  • Disable or validate the locale setting for theme translation, or implement input validation to prevent directory traversal until the patch is applied.

Generated by OpenCVE AI on October 2, 2026 at 13:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description Ghost from 1.20.0 before 6.64.0 contains a path traversal vulnerability in theme translation file loading that allows authenticated administrators to read JSON files outside the active theme directory. Attackers can manipulate the locale setting to load JSON files elsewhere on the server, exposing server configuration secrets.
Title Ghost 1.20.0 before 6.64.0 Path Traversal via Locale Setting
First Time appeared Ghost
Ghost ghost
Weaknesses CWE-22
CPEs cpe:2.3:a:ghost:ghost:*:*:*:*:*:*:*:*
Vendors & Products Ghost
Ghost ghost
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T15:42:21.293Z

Reserved: 2026-10-02T00:44:44.529Z

Link: CVE-2026-104417

cve-icon Vulnrichment

Updated: 2026-10-02T15:41:57.682Z

cve-icon NVD

Status : Received

Published: 2026-10-02T12:17:11.567

Modified: 2026-10-02T16:16:45.283

Link: CVE-2026-104417

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T14:15:14Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')