CVE WATCH / VULNERABILITY DETAIL
CVE-2026-105676
MEDIUMCVSS 4.9NVD feed
Published 5 October 2026 · tracked since 6 October 2026
Description
Ghost is a Node.js content management system. From 1.20.0 until 6.64.0, a vulnerability in how Ghost loads theme translation files allowed an authenticated Administrator to read JSON files outside of the active theme's directory, potentially exposing server configuration secrets. This issue is fixed
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-95264
- CVE-2026-97257 HIGH 8.8
- CVE-2026-93617 HIGH 7.2
- CVE-2026-105766 LOW 3.1
- CVE-2026-105767 LOW 3.3
- CVE-2026-105683 LOW 3.8
- CVE-2026-105681 MEDIUM 6.5
- CVE-2026-105682 LOW 2.7
- CVE-2026-105679 HIGH 7.3
- CVE-2026-105680 MEDIUM 6.5