---
id: CVE-2026-105676
title: Ghost is a Node.js content management system
summary: >-
  Ghost is a Node.js content management system. From 1.20.0 until 6.64.0, a
  vulnerability in how Ghost loads theme translation files allowed an
  authenticated Administrator to read JSON files outside of the active theme's
  directory, potenti…
severity: medium
cvss: 4.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-22
  - CWE-73
vendor: TryGhost
product: Ghost
affected:
  - 'Ghost >= 1.20.0, < 6.64.0'
published: '2026-10-05'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T20:17:14.547'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105676'
references:
  - url: >-
      https://github.com/TryGhost/Ghost/commit/d2f498694be549074dd5817fd0e8a1371b65df02
    label: security-advisories@github.com
  - url: 'https://github.com/TryGhost/Ghost/issues/30635'
    label: security-advisories@github.com
  - url: 'https://github.com/TryGhost/Ghost/releases/tag/v6.64.0'
    label: security-advisories@github.com
  - url: 'https://github.com/TryGhost/Ghost/security/advisories/GHSA-m382-6jw4-fmp6'
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-05T19:30:59.994Z'
---

## Overview

Ghost is a Node.js content management system. From 1.20.0 until 6.64.0, a vulnerability in how Ghost loads theme translation files allowed an authenticated Administrator to read JSON files outside of the active theme's directory, potentially exposing server configuration secrets. This issue is fixed in version 6.64.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
