---
id: CVE-2026-104417
title: >-
  Ghost from 1.20.0 before 6.64.0 contains a path traversal vulnerability in
  theme translation file loading that allows authenticated administrators to
  read JSON files outside the active theme directory
summary: >-
  Ghost from 1.20.0 before 6.64.0 contains a path traversal vulnerability in
  theme translation file loading that allows authenticated administrators to
  read JSON files outside the active theme directory. Attackers can manipulate
  the locale…
severity: medium
cvss: 4.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-22
vendor: TryGhost
product: Ghost
affected:
  - Ghost >= 1.20.0 < 6.64.0
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T12:17:11.567'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104417'
references:
  - url: 'https://github.com/TryGhost/Ghost/security/advisories/GHSA-m382-6jw4-fmp6'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/ghost-1.20.0-before-6.64.0-path-traversal-via-locale-setting
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-02T12:17:44.328Z'
---

## Overview

Ghost from 1.20.0 before 6.64.0 contains a path traversal vulnerability in theme translation file loading that allows authenticated administrators to read JSON files outside the active theme directory. Attackers can manipulate the locale setting to load JSON files elsewhere on the server, exposing server configuration secrets.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
