{"id":"BIT-ghost-2026-29053","summary":"Ghost Vulnerable to Remote Code Execution via Malicious Themes","details":"Ghost is a Node.js content management system. From version 0.7.2 to 6.19.0, specifically crafted malicious themes can execute arbitrary code on the server running Ghost. This issue has been patched in version 6.19.1.","aliases":["CVE-2026-29053","GHSA-cgc2-rcrh-qr5x"],"modified":"2026-09-08T08:47:33.225681734Z","published":"2026-03-07T08:42:59.400Z","database_specific":{"cpes":["cpe:2.3:a:ghost:ghost:*:*:*:*:*:node.js:*:*"],"severity":"Critical"},"references":[{"type":"ADVISORY","url":"https://github.com/TryGhost/Ghost/security/advisories/GHSA-cgc2-rcrh-qr5x"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-29053"}],"affected":[{"package":{"name":"ghost","ecosystem":"Bitnami","purl":"pkg:bitnami/ghost"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.7.2"},{"fixed":"6.19.1"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/ghost/BIT-ghost-2026-29053.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}],"schema_version":"1.9.0"}