CVE-2026-105676 UNKNOWN

CVE-2026-105676

Published: 2026-10-05

Description

Ghost is a Node.js content management system. From 1.20.0 until 6.64.0, a vulnerability in how Ghost loads theme translation files allowed an authenticated Administrator to read JSON files outside of the active theme's directory, potentially exposing server configuration secrets. This issue is fixed in version 6.64.0.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…