Path traversal in Ghost - #VU151107
Published: September 18, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper limitation of a pathname to a restricted directory in Ghost theme translation file loading when processing a locale setting. A remote privileged user can specify a path traversal sequence in the locale setting to read JSON files outside the active theme directory and disclose sensitive information.