Impact
Ghost versions 1.20.0 through 6.63.99 contain a path traversal flaw in theme translation file loading. The flaw allows an authenticated administrator to specify an arbitrary locale value, causing the system to load JSON files outside the active theme directory. By reading these files an attacker can obtain server configuration secrets and other sensitive data. The weakness is a classic Directory Traversal (CWE-22).
Affected Systems
The affected product is Ghost from TryGhost. Any installation of Ghost from version 1.20.0 up to, but not including, 6.64.0 is vulnerable. Upgrading beyond 6.64.0 eliminates the flaw.
Risk and Exploitability
The CVSS score is 6.9, indicating a high severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. The attack requires authenticated administrator privileges and manipulation of the locale setting; it does not rely on network exposure or remote code execution. An attacker controlling an administrator session can read arbitrary files, compromising confidentiality of server configuration and potentially other secrets.
OpenCVE Enrichment