Vulnerability GHSA-jj74-hc2q-xrvm
Summary
Ghost: Remote Code Execution via Theme Translation Files
Details
Impact
A vulnerability in how Ghost loads theme translation files allowed an authenticated Administrator to execute arbitrary code on the server via a crafted theme.
Vulnerable versions
This vulnerability is present in Ghost from v6.10.3 up to v6.64.0.
Patches
v6.64.0 contains a fix for this issue.
How to update
For self-hosters using Docker, find Docker's official Ghost image here. Updating a Docker-based Ghost instance is documented here.
If your Ghost is a Ghost-CLI install see our documentation on updating it to the latest version here.
References
Ghost thanks Miguel Segovia Gil of KPMG, Alemmi, and Tomer-PL for disclosing this vulnerability responsibly.
For more information
If you have any questions or comments about this advisory, email us at [email protected].
Related Vulnerabilities
Other vulnerabilities affecting the same packages