CVE-2026-29053
published 2026-03-05CVE-2026-29053: Ghost is a Node.js content management system. From version 0.7.2 to 6.19.0, specifically crafted malicious themes can execute arbitrary code on the server…
PriorityP268critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
0.99%
59.3th percentile
Ghost is a Node.js content management system. From version 0.7.2 to 6.19.0, specifically crafted malicious themes can execute arbitrary code on the server running Ghost. This issue has been patched in version 6.19.1.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ghost | ghost | >= 0.7.2 < 6.19.1 | 6.19.1 |
| ghost | ghost | >= 0.7.2 < 6.19.1 | 6.19.1 |
| tryghost | ghost | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Ghost Vulnerable to Remote Code Execution via Malicious Themes
osv·2026-03-03
CVE-2026-29053 [HIGH] Ghost Vulnerable to Remote Code Execution via Malicious Themes
Ghost Vulnerable to Remote Code Execution via Malicious Themes
### Impact
Specifically crafted malicious themes can execute arbitrary code on the server running Ghost.
### Vulnerable Versions
This vulnerability is present in Ghost v0.7.2 to v6.19.0.
### Patches
v6.19.1 contains a fix for this issue.
### Workarounds
Ghost generally recommends users refrain from installing untrusted themes. If a malicious theme has already been installed, it is recommended to uninstall the theme and then inspect it to understand its impact, which will be attack-specific.
### References
Ghost thanks Cristian-Alexandru Staicu at Endor Labs for disclosing this vulnerability responsibly.
### For more information
If there are any questions or comments about this advisory, email Ghost at [security@ghost
GHSA
Ghost Vulnerable to Remote Code Execution via Malicious Themes
ghsa·2026-03-03
CVE-2026-29053 [HIGH] CWE-74 Ghost Vulnerable to Remote Code Execution via Malicious Themes
Ghost Vulnerable to Remote Code Execution via Malicious Themes
### Impact
Specifically crafted malicious themes can execute arbitrary code on the server running Ghost.
### Vulnerable Versions
This vulnerability is present in Ghost v0.7.2 to v6.19.0.
### Patches
v6.19.1 contains a fix for this issue.
### Workarounds
Ghost generally recommends users refrain from installing untrusted themes. If a malicious theme has already been installed, it is recommended to uninstall the theme and then inspect it to understand its impact, which will be attack-specific.
### References
Ghost thanks Cristian-Alexandru Staicu at Endor Labs for disclosing this vulnerability responsibly.
### For more information
If there are any questions or comments about this advisory, email Ghost at [security@ghost
No detection rules found.
Rapid7
Metasploit Wrap Up: Lot of summer shells and fit http profiles
blogs_rapid7·2026-08-14·CVSS 10.0
CVE-2026-46300 [CRITICAL] Metasploit Wrap Up: Lot of summer shells and fit http profiles
This wrap-up brings a full-on shell parade. Thirteen shiny new modules landed, starting with a buffet of RCEs. WordPress WP2Shell, Ghost CMS, Joomla JCE, Langflow, OpenCATS, Pterodactyl Panel, SonicWall SMA1000, Ray Dashboard, a Pix-for-WooCommerce, and for those who like their exploits closer to the bare-metal, the Fragnesia Linux kernel LPE (CVE-2026-46300). Metasploit also got the glow-up of the summer with the new http malleable profiles, MCP functionality and linux multi fetch payloads (more details on the [official 6.5 release blog post](https://www.rapid7.com/blog/post/pt-metasploit-framework-6-5-released/)!). Windows on ARM confirm to be the new first-class citizenship thanks to brand-new AArch64 reverse-TCP shells (both inline and staged), so your Snapdragon boxes can join the par
Wiz
CVE-2026-29053 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.6
CVE-2026-29053 [HIGH] CVE-2026-29053 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-29053 :
JavaScript vulnerability analysis and mitigation
Ghost is a Node.js content management system. From version 0.7.2 to 6.19.0, specifically crafted malicious themes can execute arbitrary code on the server running Ghost. This issue has been patched in version 6.19.1.
Source : NVD
## 9.8
Score
Published March 5, 2026
Severity CRITICAL
CNA Score 7.6
Affected Technologies
JavaScript
NixOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 23.1
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
ghost
Sources
NVD
npm Severity HIGH Has Fix Added at: Mar 04, 2026
Nix Severity CRITICAL Has Fix Added at: Mar 10, 2026
## Get a CVE risk assessment
Get a
2026-03-05
Published