CVE-2026-105676Medium· 4.9▾ SunlitGhost is a Node.js content management system. From 1.20.0 until 6.64.0, a vulnerability in how Ghost loads theme translation files allowed an authenticated Administrator to read JSON files outside of the active theme's directory, potenti…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Ghost is a Node.js content management system. From 1.20.0 until 6.64.0, a vulnerability in how Ghost loads theme translation files allowed an authenticated Administrator to read JSON files outside of the active theme's directory, potentially exposing server configuration secrets. This issue is fixed in version 6.64.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-105677High· 7.2Ghost is a Node.js content management system
CVE-2026-104417Medium· 4.9Ghost from 1.20.0 before 6.64.0 contains a path traversal vulnerability in theme translation file loading that allows authenticated administrators to read JSON files outside the active theme directory
CVE-2026-105679High· 7.3Ghost is a Node.js content management system
CVE-2026-105678Medium· 4.3Ghost is a Node.js content management system
CVE-2026-105650High· 8.1Ghost is a Node.js content management system
CVE-2026-105651High· 7.3Ghost is a Node.js content management system