Description
Ghost from 6.10.3 before 6.64.0 contains a remote code execution vulnerability that allows authenticated administrators to run code by abusing theme translation file loading. Attackers with administrator access can upload a crafted theme containing malicious translation files to execute arbitrary code on the Ghost server.
Published: 2026-10-02
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a remote code execution flaw that arises when an authenticated administrator uploads a theme containing malicious translation files. The attacker can craft a theme that includes code designed to be executed when the Ghost server loads the translation files, allowing the attacker to run arbitrary code with the privileges of the Ghost application.

Affected Systems

The affected vendor is TryGhost, with the product Ghost. The flaw exists in versions from 6.10.3 up to, but not including, 6.64.0. Any installation within this range that accepts theme uploads is susceptible.

Risk and Exploitability

The CVSS score of 8.6 indicates a high severity risk. No EPSS score is available, so the exploitation probability is unknown, and the vulnerability is not listed in CISA KEV. The likely attack vector is an authenticated administrator who can upload themes. Exploitation requires administrator credentials and the ability to place files in the theme directory. Once the malicious translation file is processed, arbitrary code runs on the server.

Generated by OpenCVE AI on October 2, 2026 at 12:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Ghost to version 6.64.0 or later, which removes the vulnerability.
  • If an upgrade is not immediately possible, apply any available vendor‑issued security patch for the specific version.
  • Restrict theme upload permissions to a minimal set of trusted administrators and enforce strict file type and size validation.
  • Perform a security audit of existing theme directories to detect and remove any potentially malicious files.

Generated by OpenCVE AI on October 2, 2026 at 12:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description Ghost from 6.10.3 before 6.64.0 contains a remote code execution vulnerability that allows authenticated administrators to run code by abusing theme translation file loading. Attackers with administrator access can upload a crafted theme containing malicious translation files to execute arbitrary code on the Ghost server.
Title Ghost from 6.10.3 before 6.64.0 RCE via Theme Translation Files
First Time appeared Ghost
Ghost ghost
Weaknesses CWE-22
CPEs cpe:2.3:a:ghost:ghost:*:*:*:*:*:*:*:*
Vendors & Products Ghost
Ghost ghost
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T11:38:00.453Z

Reserved: 2026-10-02T00:44:44.529Z

Link: CVE-2026-104418

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T12:17:11.710

Modified: 2026-10-02T12:17:11.710

Link: CVE-2026-104418

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T14:15:14Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')