Sceawere

Vulnerability Detail

CVE-2026-105677UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Ghost Arbitrary Code Execution Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
1h ago
Vendor
TryGhost
Product
Ghost
Attack Type
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Ghost is a Node.js content management system. From 6.10.3 until 6.64.0, a vulnerability in how Ghost loads theme translation files allowed an authenticated Administrator to execute arbitrary code on the server via a crafted theme. This issue is fixed in version 6.64.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-10-05T20:17:14.733Z",
  "pubdate": "2026-10-05T20:17:14.733Z",
  "executiveSummary": "A critical security vulnerability exists within the Ghost content management system, specifically involving the improper processing of theme translation files. This flaw allows an authenticated user with Administrative privileges to achieve Remote Code Execution (RCE) on the underlying host server. The vulnerability stems from insecure handling of localized theme components, enabling the injection and subsequent execution of arbitrary code.\nThe scope of this vulnerability affects Ghost versions from 6.10.3 through 6.64.0. The risk profile is considered high because it grants an attacker full control over the application server, potentially leading to unauthorized data access, system compromise, or lateral movement within the hosting environment. Successful exploitation requires administrative access to the Ghost instance, meaning the threat originates from a compromised or malicious insider account with elevated permissions. Organizations utilizing Ghost are urged to update to version 6.64.0 immediately to remediate the flaw and prevent potential server-side exploitation.",
  "technicalDetails": "The vulnerability resides within the theme management subsystem of Ghost, specifically in the logic responsible for parsing and loading theme translation files (e.g., .json or other locale-specific formats). In affected versions (6.10.3 to 6.64.0), the application fails to adequately sanitize or validate the content and metadata of these translation files when they are bundled within a theme package.\nThe root cause is an insecure deserialization or improper input validation routine where the translation loading mechanism processes untrusted file content as executable instructions or template logic. When an Administrator uploads a crafted theme, the application performs an internal extraction and traversal process to map the locale files. During this phase, the application treats the translation file structure as a trusted configuration; however, it lacks the necessary constraints to prevent the inclusion of malicious payloads that can interact with the underlying Node.js runtime environment.\nThe attack flow proceeds as follows: First, the attacker creates a malicious theme archive containing a modified translation file. This file is crafted to contain specific directives or code patterns that exploit the way Ghost's translation engine parses or interprets keys and values. Second, the attacker uploads this crafted theme through the administrative dashboard, which serves as the primary vector. Third, upon theme activation or during the system's scanning of the theme directory, the Ghost engine processes the malicious translation file. The underlying vulnerability allows the payload to escape the expected data context and execute code within the Node.js process hosting the Ghost application.\nBecause the Ghost application executes with the permissions of the service user, the resulting code execution allows the attacker to perform arbitrary actions, including reading sensitive configuration files, modifying the database, or spawning reverse shells to gain persistent access to the operating system. This mechanism bypasses typical file-type restrictions because the payload is encapsulated within the theme file structure that is inherently permitted for administrative use. The exploitation is persistent and remains active until the malicious theme is removed or the underlying code logic is patched. The vulnerability is effectively mitigated by validating the schema of translation files and sandboxing the parser to prevent unintended interaction with the Node.js process environment."
}
CVE-2026-105677: Ghost Arbitrary Code Execution Vulnerability (HIGH Severity, CVSS: 7.2) | Sceawere