Specifically crafted malicious themes can execute arbitrary code on the server running Ghost.
This vulnerability is present in Ghost v0.7.2 to v6.19.0.
v6.19.1 contains a fix for this issue.
Ghost generally recommends users refrain from installing untrusted themes. If a malicious theme has already been installed, it is recommended to uninstall the theme and then inspect it to understand its impact, which will be attack-specific.
Ghost thanks Cristian-Alexandru Staicu at Endor Labs for disclosing this vulnerability responsibly.
If there are any questions or comments about this advisory, email Ghost at security@ghost.org.
{
"github_reviewed": true,
"github_reviewed_at": "2026-03-03T20:01:21Z",
"cwe_ids": [
"CWE-74"
],
"severity": "HIGH",
"nvd_published_at": "2026-03-05T06:16:50Z"
}