PT-2026-23004 · Ghost · Ghost

Cristianstaicu

·

Published

2026-03-03

·

Updated

2026-04-24

·

CVE-2026-29053

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ghost versions 0.7.2 through 6.19.0
Description Ghost, a Node.js content management system, is affected by a code execution issue. Maliciously crafted themes can execute arbitrary code on the server. It is recommended to avoid installing untrusted themes. If a malicious theme has already been installed, uninstall it and inspect it to understand its impact.
Recommendations Update to version 6.19.1 or later. Uninstall any malicious themes. Inspect installed themes for potential impact.

Exploit

Fix

RCE

Special Elements Injection

Weakness Enumeration

Related Identifiers

BIT-GHOST-2026-29053
CVE-2026-29053
GHSA-CGC2-RCRH-QR5X

Affected Products

Ghost