Vulnerability
Published 2026-09-02
Verified 2026-09-19

Ghost CMS malicious-theme RCE (CVE-2026-29053); Metasploit module public

Exploit-DB entry 52676 (dated 2 September 2026) packages a Metasploit module for CVE-2026-29053: crafted Ghost CMS themes can execute arbitrary code on the host. The module lists affected releases from 0.7.2 through 6.19.0 and notes that for versions 5.105.0–5.130.5 and 6.0.0–6.10.3 it can also leverage a related 2FA bypass (CVE-2026-22594). Endor Labs write-up GHSA-cgc2-rcrh-qr5x is cited as the research reference. Upgrade Ghost past the fixed releases; restrict who can upload themes; review installed themes for unexpected Handlebars templates.

Product
Ghost CMS
Versions
≥0.7.2 ≤6.19.0 per Metasploit module; 2FA-bypass assist on 5.105.0–5.130.5 and 6.0.0–6.10.3
Exploited in Australia?
unknown
Patch to
Upgrade Ghost to vendor-fixed release; limit theme upload; audit custom themes

Primary: Endor Labs (Ghost CMS RCE) · Vendor: Ghost · CVE: CVE-2026-29053, CVE-2026-22594 · Exploit-DB 52676 / Metasploit (2 Sep 2026)

vulnerabilities cloud