Launch Week Day 1: Announcing Security Design Review
HIGH 7.6 npm

Ghost Vulnerable to Remote Code Execution via Malicious Themes

GHSA-cgc2-rcrh-qr5x · BIT-ghost-2026-29053 · CVE-2026-29053

Published · Modified

Description

Impact

Specifically crafted malicious themes can execute arbitrary code on the server running Ghost.

Vulnerable Versions

This vulnerability is present in Ghost v0.7.2 to v6.19.0.

Patches

v6.19.1 contains a fix for this issue.

Workarounds

Ghost generally recommends users refrain from installing untrusted themes. If a malicious theme has already been installed, it is recommended to uninstall the theme and then inspect it to understand its impact, which will be attack-specific.

References

Ghost thanks Cristian-Alexandru Staicu at Endor Labs for disclosing this vulnerability responsibly.

For more information

If there are any questions or comments about this advisory, email Ghost at security@ghost.org.

Ready to move

Start Securing

Free, no credit card | First findings in minutes