CVE-2026-104417

medium

Description

Ghost from 1.20.0 before 6.64.0 contains a path traversal vulnerability in theme translation file loading that allows authenticated administrators to read JSON files outside the active theme directory. Attackers can manipulate the locale setting to load JSON files elsewhere on the server, exposing server configuration secrets.

References

https://www.vulncheck.com/advisories/ghost-1.20.0-before-6.64.0-path-traversal-via-locale-setting

https://github.com/TryGhost/Ghost/security/advisories/GHSA-m382-6jw4-fmp6

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-91428

Details

Source: Mitre, NVD

Published: 2026-10-02

Updated: 2026-10-02

Risk Information

CVSS v2

Base Score: 6.1

Vector: CVSS2#AV:N/AC:L/Au:M/C:C/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 4.9

Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Severity: Medium

CVSS v4

Base Score: 6.9

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Severity: Medium

EPSS

EPSS: 0.00366