CVE-2026-104418: Ghost from 6.10.3 before 6.64.0 RCE via Theme Translation Files
Published Oct 2, 2026
·Updated
Ghost from 6.10.3 before 6.64.0 contains a remote code execution vulnerability that allows authenticated administrators to run code by abusing theme translation file loading. Attackers with administrator access can upload a crafted theme containing malicious translation files to execute arbitrary code on the Ghost server.
Affected Software
1 affected component
Ghost Ghost>=6.10.3<6.64.0
Event History
Oct 2, 2026
CVE Published
via MITRE·11:38 AM
Data Sourced
via MITRE·11:38 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
Ghost versions from 6.10.3 before 6.64.0 are affected. The issue involves theme translation file loading.
2
What access does an attacker need to exploit this?
An attacker needs authenticated administrator access to Ghost. They must be able to upload a crafted theme containing malicious translation files.
3
What is the impact of successful exploitation?
Successful exploitation allows arbitrary code execution on the Ghost server. This can affect confidentiality, integrity, and availability.