Arbitrary Code Execution in Ghost CMS Versions 6.10.3 to 6.64.0
CVE-2026-105677
7.2HIGH
What is CVE-2026-105677?
A vulnerability in Ghost, a popular Node.js content management system, allows authenticated Administrators to execute arbitrary code on the server by loading crafted theme translation files. This issue is present in versions 6.10.3 to 6.64.0 and has been addressed in version 6.64.0.
Affected Version(s)
Ghost >= 6.10.3, < 6.64.0
