CVE-2026-104418 PUBLISHED

Ghost from 6.10.3 before 6.64.0 RCE via Theme Translation Files

Assigner: VulnCheck
Reserved: 02.10.2026 Published: 02.10.2026 Updated: 02.10.2026

Ghost from 6.10.3 before 6.64.0 contains a remote code execution vulnerability that allows authenticated administrators to run code by abusing theme translation file loading. Attackers with administrator access can upload a crafted theme containing malicious translation files to execute arbitrary code on the Ghost server.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.6

Product Status

Vendor TryGhost
Product Ghost
Versions Default: unaffected
  • affected from 6.10.3 to 6.64.0 (excl.)
  • Version 6.64.0 is unaffected

Credits

  • Alemmi reporter
  • Tomer-PL reporter
  • msegoviag reporter

References

Problem Types

  • Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE