A vulnerability in how Ghost loads theme translation files allowed an authenticated Administrator to execute arbitrary code on the server via a crafted theme.
This vulnerability is present in Ghost from v6.10.3 up to v6.64.0.
v6.64.0 contains a fix for this issue.
For self-hosters using Docker, find Docker's official Ghost image here. Updating a Docker-based Ghost instance is documented here.
If your Ghost is a Ghost-CLI install see our documentation on updating it to the latest version here.
Ghost thanks Miguel Segovia Gil of KPMG, Alemmi, and Tomer-PL for disclosing this vulnerability responsibly.
If you have any questions or comments about this advisory, email us at security@ghost.org.
{
"cwe_ids": [
"CWE-22",
"CWE-829",
"CWE-94"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-07T20:26:08Z",
"nvd_published_at": "2026-10-05T20:17:14Z",
"severity": "HIGH"
}