CVE-2026-29053
Ghost is a Node.js content management system. From version 0.7.2 to 6.19.0, specifically crafted malicious themes can execute arbitrary code on the server running Ghost. This issue has been patched in version 6.19.1.
- Affected products
- Ghost
- Ghost
- < 6.19.1
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 1.4% (70th percentile)
- Weakness
- CWE-74
- NVD status
- Analyzed
- Published
- 2026-03-05
CVE-2026-29053 at NVD
6 known exploits for CVE-2026-29053
Proof-of-concept code and exploit modules indexed by Sploitus