CVE-2026-29053Disclosure(ghost / ghost)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch ghost ghost systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Ghost is a Node.js content management system. From version 0.7.2 to 6.19.0, specifically crafted malicious themes can execute arbitrary code on the server running Ghost. This issue has been patched in version 6.19.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ghost

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-08); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
ghost

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-05: 1Mentions · 2026-03-08: 2Mentions · 2026-04-24: 1Patch / Workaround · 2026-03-08: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-08: 2Technical Details · 2026-04-24: 103-0503-0804-24
Signal classification3 categories
Disclosure
250.0%
Patch
125.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-051
Disclosure1
2026-03-082
Disclosure1Patch1
2026-04-241
General1
Full discourse4 posts
  • DailyCVE@dailycve
    General

    🟠 #Azure/go-ntlmssp, Slice Out of Bounds, #CVE-2026-29053 (Moderate) https://dailycve.com/azure-go-ntlmssp-slice-out-of-bounds-cve-2026-29053-moderate/

    Post summary

    The post references CVE-2026-29053, a slice out-of-bounds issue in Azure go-ntlmssp, but offers only basic technical details and no PoC, exploit, or patch information.

    0000058
    183 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-29053 Ghost is a Node.js content management system. From version 0.7.2 to 6.19.0, specifically crafted malicious themes can execute arbitrary code on the server running Gho… https://www.cve.org/CVERecord?id=CVE-2026-29053

    Post summary

    CVE-2026-29053 enables arbitrary code execution via malicious Ghost CMS themes on versions 0.7.2 through 6.19.0, with no PoC, exploit, or patch details provided.

    00000196
    56.6K followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    `Ghost` versions prior to 6.19.1 are vulnerable to remote code execution (CVE-2026-29053) via malicious themes. Update promptly to mitigate risks. #GhostCMS #RCE #infosec https://www.pulsepatch.io/posts/cve-2026-29053-ghost-rce-malicious-themes

    Post summary

    The tweet warns that Ghost CMS versions prior to 6.19.1 are vulnerable to RCE through malicious themes and urges users to update immediately to mitigate the risk.

    0000036
    1 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-29053 Arbitrary Code Execution in Ghost CMS via Malicious Themes Before 6.19.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-29053

    Post summary

    The text announces the discovery of an arbitrary code execution vulnerability in Ghost CMS via malicious themes before version 6.19.1.

    0000034
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appghostghost-node.js-

Explore more