CVE-2026-105677

Summary

Ghost is a Node.js content management system. From 6.10.3 until 6.64.0, a vulnerability in how Ghost loads theme translation files allowed an authenticated Administrator to execute arbitrary code on the server via a crafted theme. This issue is fixed in version 6.64.0.

Affected Software

VendorProductVersion RangeStatus
TryGhostGhost>= 6.10.3, < 6.64.0affected

Weaknesses

  • CWE-22: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
  • CWE-94: CWE-94: Improper Control of Generation of Code ('Code Injection')
  • CWE-829: CWE-829: Inclusion of Functionality from Untrusted Control Sphere

References