CVE-2026-29053

Source
https://cve.org/CVERecord?id=CVE-2026-29053
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-29053.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-29053
Aliases
Published
2026-03-05T05:51:41Z
Modified
2026-08-12T03:51:40Z
Severity
  • 7.6 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H CVSS Calculator
Summary
Ghost Vulnerable to Remote Code Execution via Malicious Themes
Details

Ghost is a Node.js content management system. From version 0.7.2 to 6.19.0, specifically crafted malicious themes can execute arbitrary code on the server running Ghost. This issue has been patched in version 6.19.1.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-74"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/29xxx/CVE-2026-29053.json"
}
References

Affected packages

Git / github.com/tryghost/ghost

Affected ranges

Type
GIT
Repo
https://github.com/tryghost/ghost
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:ghost:ghost:*:*:*:*:*:node.js:*:*",
    "extracted_events": [
        {
            "introduced": "0.7.2"
        },
        {
            "fixed": "6.19.1"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE"
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-29053.json"