GHSA-jj74-hc2q-xrvm

Suggest an improvement
Source
https://github.com/advisories/GHSA-jj74-hc2q-xrvm
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-jj74-hc2q-xrvm/GHSA-jj74-hc2q-xrvm.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-jj74-hc2q-xrvm
Aliases
Published
2026-10-07T20:26:08Z
Modified
2026-10-07T20:30:04Z
Severity
  • 7.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Ghost: Remote Code Execution via Theme Translation Files
Details

Impact

A vulnerability in how Ghost loads theme translation files allowed an authenticated Administrator to execute arbitrary code on the server via a crafted theme.

Vulnerable versions

This vulnerability is present in Ghost from v6.10.3 up to v6.64.0.

Patches

v6.64.0 contains a fix for this issue.

How to update

For self-hosters using Docker, find Docker's official Ghost image here. Updating a Docker-based Ghost instance is documented here.

If your Ghost is a Ghost-CLI install see our documentation on updating it to the latest version here.

References

Ghost thanks Miguel Segovia Gil of KPMG, Alemmi, and Tomer-PL for disclosing this vulnerability responsibly.

For more information

If you have any questions or comments about this advisory, email us at security@ghost.org.

Database specific
{
    "cwe_ids": [
        "CWE-22",
        "CWE-829",
        "CWE-94"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-07T20:26:08Z",
    "nvd_published_at": "2026-10-05T20:17:14Z",
    "severity": "HIGH"
}
References

Affected packages

npm / ghost

Package

Affected ranges

Type
SEMVER
Events
Introduced
6.10.3
Fixed
6.64.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-jj74-hc2q-xrvm/GHSA-jj74-hc2q-xrvm.json"