Sceawere

Vulnerability Detail

CVE-2026-105676UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Ghost Arbitrary File Read Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.9
Creation Date
1h ago
Vendor
TryGhost
Product
Ghost
Attack Type
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Ghost is a Node.js content management system. From 1.20.0 until 6.64.0, a vulnerability in how Ghost loads theme translation files allowed an authenticated Administrator to read JSON files outside of the active theme's directory, potentially exposing server configuration secrets. This issue is fixed in version 6.64.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.9",
  "pubDate": "2026-10-05T20:17:14.547Z",
  "pubdate": "2026-10-05T20:17:14.547Z",
  "executiveSummary": "A directory traversal vulnerability exists in the Ghost content management system, specifically within the theme translation file loading mechanism. The flaw permits an authenticated Administrator to bypass directory restrictions and perform arbitrary read operations on JSON files located outside the intended theme directory. This vulnerability poses a significant risk to server confidentiality, as it facilitates the exfiltration of sensitive configuration files, environment secrets, and internal system data. The issue affects Ghost versions 1.20.0 through 6.64.0. Exploitation requires authenticated administrative access to the platform, making it a critical concern for multi-user environments or instances where administrative accounts may be compromised. By manipulating the theme translation loading process, an attacker can leverage the application's file-handling logic to access files on the host filesystem that are otherwise inaccessible, potentially leading to a full compromise of the application's underlying security infrastructure.",
  "technicalDetails": "The vulnerability originates from improper validation of file paths when Ghost processes and loads theme translation files (i.e., .json files used for internationalization). Within the theme management subsystem, the application fails to adequately sanitize path inputs or enforce sandbox constraints when resolving the location of these translation files. This enables a directory traversal attack, wherein an adversary can inject path-traversal sequences (e.g., ../) into the file selection or theme-loading parameters.\nThe attack flow initiates with the authenticated Administrator accessing the theme management interface. By providing a crafted path directed outside the authorized theme directory, the attacker tricks the application's file-system abstraction layer into traversing the directory structure. Because the application logic treats the input as a legitimate translation file, it attempts to load and parse the referenced JSON file. This results in the contents of the target file being read and potentially returned or leaked through the application response.\nThe root cause is a lack of path normalization and validation logic within the Ghost theme-loading component. The application fails to verify that the target file resides strictly within the expected base directory. By exploiting this, an attacker can navigate to sensitive locations such as the root directory of the application, configuration folders (e.g., config.production.json), or other directories containing sensitive credentials, database connection strings, or system environment variables.\nThis vulnerability is classified as an Arbitrary File Read, stemming from insufficient input sanitization. The impact is significant because it grants the attacker the ability to retrieve contents of any JSON-formatted file the Ghost process user has read permissions for. This often includes critical infrastructure secrets that, when compromised, can lead to full administrative takeover, database exposure, or remote code execution if configuration secrets (such as mail server credentials or session secret keys) are exfiltrated. The vulnerability is present across Ghost versions 1.20.0 to 6.64.0 and is successfully mitigated in version 6.64.0, which presumably implements stricter path validation or a chroot-like mechanism to ensure translation files are only sourced from validated, intended directories."
}
CVE-2026-105676: Ghost Arbitrary File Read Vulnerability (MEDIUM Severity, CVSS: 4.9) | Sceawere