Vulnerability GHSA-jj74-hc2q-xrvm

High Risk
HIGH RISK
CVSS Score: 7.2
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
1 day ago
October 07, 2026 at 08:26 PM UTC
Ghost: Remote Code Execution via Theme Translation Files
6.10.3 - 6.63.0
6.10.3 - 6.63.0

Summary

Ghost: Remote Code Execution via Theme Translation Files

Details

Impact

A vulnerability in how Ghost loads theme translation files allowed an authenticated Administrator to execute arbitrary code on the server via a crafted theme.

Vulnerable versions

This vulnerability is present in Ghost from v6.10.3 up to v6.64.0.

Patches

v6.64.0 contains a fix for this issue.

How to update

For self-hosters using Docker, find Docker's official Ghost image here. Updating a Docker-based Ghost instance is documented here.

If your Ghost is a Ghost-CLI install see our documentation on updating it to the latest version here.

References

Ghost thanks Miguel Segovia Gil of KPMG, Alemmi, and Tomer-PL for disclosing this vulnerability responsibly.

For more information

If you have any questions or comments about this advisory, email us at [email protected].

Impacted packages

Timeline

Published
1 day ago
October 07, 2026 at 08:26 PM UTC
Fixed (6.64.0)
Unknown
Unknown
Last Modified
4 hours ago
October 09, 2026 at 12:11 PM UTC