Impact
The vulnerability is a remote code execution flaw that arises when an authenticated administrator uploads a theme containing malicious translation files. The attacker can craft a theme that includes code designed to be executed when the Ghost server loads the translation files, allowing the attacker to run arbitrary code with the privileges of the Ghost application.
Affected Systems
The affected vendor is TryGhost, with the product Ghost. The flaw exists in versions from 6.10.3 up to, but not including, 6.64.0. Any installation within this range that accepts theme uploads is susceptible.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity risk. No EPSS score is available, so the exploitation probability is unknown, and the vulnerability is not listed in CISA KEV. The likely attack vector is an authenticated administrator who can upload themes. Exploitation requires administrator credentials and the ability to place files in the theme directory. Once the malicious translation file is processed, arbitrary code runs on the server.
OpenCVE Enrichment