CVE-2026-29053

Source
https://cve.org/CVERecord?id=CVE-2026-29053
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-29053.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-29053
Aliases
Published
2026-03-05T05:51:41.166Z
Modified
2026-04-10T05:41:27.455384Z
Severity
  • 7.6 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H CVSS Calculator
Summary
Ghost Vulnerable to Remote Code Execution via Malicious Themes
Details

Ghost is a Node.js content management system. From version 0.7.2 to 6.19.0, specifically crafted malicious themes can execute arbitrary code on the server running Ghost. This issue has been patched in version 6.19.1.

Database specific
{
    "cwe_ids": [
        "CWE-74"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/29xxx/CVE-2026-29053.json"
}
References

Affected packages

Git / github.com/tryghost/ghost

Affected ranges

Type
GIT
Repo
https://github.com/tryghost/ghost
Events

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-29053.json"