CVE-2026-29053
Ghost is a Node.js content management system. From version 0.7.2 to 6.19.0, specifically crafted malicious themes can execute arbitrary code on the server running Ghost. This issue has been patched in version 6.19.1.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/29xxx/CVE-2026-29053.json, https://github.com/TryGhost/Ghost/security/advisories/GHSA-cgc2-rcrh-qr5x, https://nvd.nist.gov/vuln/detail/CVE-2026-29053
