Home

Description

Ghost is a Node.js content management system. From version 0.7.2 to 6.19.0, specifically crafted malicious themes can execute arbitrary code on the server running Ghost. This issue has been patched in version 6.19.1.

PUBLISHED Reserved 2026-03-03 | Published 2026-03-05 | Updated 2026-03-05 | Assigner GitHub_M




HIGH: 7.7CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H

Problem types

CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Product status

>= 0.7.2, < 6.19.1
affected

References

github.com/.../Ghost/security/advisories/GHSA-cgc2-rcrh-qr5x

cve.org (CVE-2026-29053)

nvd.nist.gov (CVE-2026-29053)

Download JSON