Sceawere
Vulnerability Detail
CVE-2026-104418UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Ghost Theme Translation RCE
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 11h ago
- Vendor
- TryGhost
- Product
- Ghost
- Attack Type
- Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Ghost from 6.10.3 before 6.64.0 contains a remote code execution vulnerability that allows authenticated administrators to run code by abusing theme translation file loading. Attackers with administrator access can upload a crafted theme containing malicious translation files to execute arbitrary code on the Ghost server.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-10-02T12:17:11.710Z",
"pubdate": "2026-10-02T12:17:11.710Z",
"executiveSummary": "This vulnerability is a critical remote code execution (RCE) flaw discovered within the Ghost CMS, specifically impacting versions 6.10.3 through 6.63.x. The vulnerability originates from improper handling of theme translation files, allowing an authenticated administrator to achieve arbitrary code execution on the underlying server host.\nThe attack vector requires the target system to be running a vulnerable version of Ghost and necessitates that the attacker possesses valid administrator-level credentials. By uploading a maliciously crafted theme file that contains a specifically designed translation component, an attacker can bypass existing security controls and force the application to execute arbitrary code within the server's execution context.\nThe risk implication is severe, as successful exploitation grants the attacker full control over the Ghost application environment. This could lead to complete system compromise, data exfiltration, unauthorized administrative actions, and persistence within the infrastructure. Because the vulnerability involves file handling and translation processing, it highlights a failure in input validation and secure file processing routines when interacting with administrative theme uploads.",
"technicalDetails": "The vulnerability exists within the theme management subsystem of the Ghost CMS. The root cause is identified as an insecure implementation of the file parsing logic responsible for processing and loading theme-specific translation files. Ghost themes allow for internationalization, which typically utilizes translation files (often in JSON or structured formats) to translate template strings.\nThe exploitation mechanism leverages the administrative capability to upload custom themes via the Ghost admin interface. An attacker creates a malicious theme package where the translation file is structured to include a payload that the application's translation engine improperly interprets as executable code or command-line instructions. Due to the lack of sufficient sanitization and validation on the contents of these uploaded files, the application engine executes the injected payload during the theme rendering or loading process.\nThe attack flow follows a sequential path: First, the attacker authenticates as an administrator within the Ghost dashboard. Second, the attacker prepares a crafted ZIP archive containing a theme structure, specifically targeting the translation directory. Third, the attacker initiates the theme upload function. Upon successful upload, the application attempts to parse the malicious translation file. The underlying engine, failing to isolate or sanitize the input, triggers the malicious code execution, resulting in arbitrary commands being run under the privileges of the Node.js process hosting the Ghost application.\nVulnerable components include the internal theme ingestion logic and the associated translation file loader. This process is susceptible to arbitrary code execution because the system trusts the contents of the uploaded files without adequate sandboxing or integrity verification. The flaw impacts Ghost versions starting from 6.10.3 and remains present until version 6.64.0.\nPost-exploitation impact is catastrophic. Because Ghost typically runs as a service, the attacker inherits the system permissions of the service user, allowing for lateral movement, file system access, and potential interaction with the underlying database or environment variables containing sensitive configuration details. The requirement for administrator access acts as an authentication barrier but provides a significant escalation path once breached, enabling full system takeover by a privileged user or an attacker who has successfully compromised an administrative account."
}