CVE-2026-104417

Source
https://cve.org/CVERecord?id=CVE-2026-104417
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-104417.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-104417
Aliases
  • GHSA-m382-6jw4-fmp6
Published
2026-10-02T11:37:59Z
Modified
2026-10-04T02:45:48Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Ghost 1.20.0 before 6.64.0 Path Traversal via Locale Setting
Details

Ghost from 1.20.0 before 6.64.0 contains a path traversal vulnerability in theme translation file loading that allows authenticated administrators to read JSON files outside the active theme directory. Attackers can manipulate the locale setting to load JSON files elsewhere on the server, exposing server configuration secrets.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-22"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/104xxx/CVE-2026-104417.json"
}
References

Affected packages

Git / github.com/tryghost/ghost

Affected ranges

Type
GIT
Repo
https://github.com/tryghost/ghost
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "1.20.0"
        },
        {
            "fixed":  "6.64.0"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-104417.json"