CVE-2026-104417 PUBLISHED

Ghost 1.20.0 before 6.64.0 Path Traversal via Locale Setting

Assigner: VulnCheck
Reserved: 02.10.2026 Published: 02.10.2026 Updated: 02.10.2026

Ghost from 1.20.0 before 6.64.0 contains a path traversal vulnerability in theme translation file loading that allows authenticated administrators to read JSON files outside the active theme directory. Attackers can manipulate the locale setting to load JSON files elsewhere on the server, exposing server configuration secrets.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor TryGhost
Product Ghost
Versions Default: unaffected
  • affected from 1.20.0 to 6.64.0 (excl.)
  • Version 6.64.0 is unaffected

Credits

  • DONG2209 reporter
  • msegoviag reporter

References

Problem Types

  • Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE