CVE-2026-29053 is an arbitrary code execution vulnerability in the Ghost Node.js content management system. Affected versions are 0.7.2 through 6.19.0. The issue allows a specifically crafted malicious theme to execute arbitrary code on the server running Ghost. Based on the available information, exploitation occurs through Ghost's theme handling or processing logic, but the specific vulnerable function or code path is not provided in the supplied content. The vulnerability is patched in Ghost 6.19.1.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This three-file repository is an operational Python PoC for the claimed Ghost CMS CVE-2026-29053 malicious-theme remote-code-execution issue. Its sole code file, exploit.py, uses requests to authenticate or attempt initial owner setup, builds a minimal Ghost theme ZIP entirely in memory, uploads and activates that theme, creates a trigger page, and requests the page to execute an injected JavaScript expression during Handlebars rendering. The generated archive contains standard theme templates plus page-rce.hbs, whose #get filter carries the prototype/constructor-based JavaScript injection. Default exploitation writes a proof file; optional shell mode uses Node.js net and child_process functionality to connect back and run /bin/bash -i. The same script includes a threaded scanner that queries the Ghost Admin site endpoint and performs a version-range check. requirements.txt lists requests, rich, pwncat, alive-progress, and exploit-utils; exploit_utils supplies the argument parser. README.md documents the attack flow, affected range, and usage. No fixed target host is embedded: the target URL, scan list, proof path, and callback host/port are operator-provided.
This repository is a real exploit for CVE-2026-29053 affecting Ghost CMS <= 6.19.0. Its main purpose is to generate a malicious Ghost theme ZIP that weaponizes a Handlebars/JSONPath injection path to achieve server-side JavaScript execution inside the Ghost process. Repository structure: - exploit.py: primary exploit entry point. It accepts attacker IP/port, rewrites poc/page-rce.hbs with a malicious Handlebars template, and packages the poc/ directory into a theme archive (default: malicious-theme.zip). - poc/: a modified copy of the Ghost 'Source' theme. Most files are benign theme assets/templates included so the uploaded theme passes Ghost validation and can be activated successfully. - poc/page-rce.hbs: the malicious template used for exploitation. It is the key payload-bearing file. - README.md and poc/CVE-2026-29053-POC.md: explain the vulnerability, usage flow, and example payloads. - build/: Docker-based lab environment for spinning up a vulnerable Ghost 6.19.0 instance, including explicit installation of vulnerable dependencies. Exploit behavior: - The Python script injects attacker-controlled IP and port into a Handlebars template. - The template abuses Ghost's use of jsonpath/static-eval via the {{#get}} helper and a crafted @site[...] expression. - The payload reaches the JavaScript Function constructor through prototype manipulation and executes arbitrary Node.js code. - The default payload creates an outbound net.Socket connection to the attacker, listens for incoming command data, executes commands with child_process.exec, and writes stdout/stderr back over the socket. Operational flow described by the repo: 1. Run exploit.py with attacker callback IP/port. 2. Start a listener (e.g., netcat) on the chosen port. 3. Upload and activate the generated malicious theme in Ghost Admin. 4. Create a page with slug 'rce'. 5. Visit /rce/ to trigger code execution. Notable observations: - This is not merely a detector or documentation-only repo; it contains working exploit generation code and a usable payload. - The included theme files are largely camouflage/compatibility scaffolding so Ghost accepts the malicious theme. - The Docker lab strongly indicates the intended vulnerable target version is Ghost 6.19.0, though the docs state <= 6.19.0 and fixed in 6.19.1.
Repository purpose: provides an operational proof-of-concept exploit for CVE-2026-29053 (Ghost CMS RCE) plus a Dockerized vulnerable environment and a malicious Ghost theme. Core exploit capability: - Achieves server-side RCE in Ghost CMS by abusing a Handlebars template expression that is evaluated through Ghost’s JSONPath handling (jsonpath + static-eval). The payload uses a prototype-chain trick to reach the JavaScript Function constructor (via {__proto__: "".toString}["constructor"]) and executes arbitrary Node.js code. - The default payload is a connect-back command channel: it creates a net.Socket to attacker-controlled IP/port, then executes any received data as an OS command using child_process.exec and returns stdout/stderr over the same socket. How exploitation is delivered: - The exploit is packaged as a Ghost theme ZIP. Ghost allows custom page templates named page-<slug>.hbs; the repo uses page-rce.hbs so that creating a page with slug 'rce' and visiting /rce/ triggers rendering and thus code execution. - exploit.py automates generating the malicious theme by overwriting poc/page-rce.hbs with a payload containing the operator-supplied IP/port, then zipping the entire poc/ theme directory into malicious-theme.zip. Repository structure highlights: - exploit.py: main generator for the malicious theme zip; takes -i (IP), -p (port), optional -o output zip name. - poc/: a full Ghost theme (based on Ghost Foundation’s “Source” theme) with an added/overwritten page-rce.hbs template used to trigger the vulnerability. - build/: Dockerfile + scripts to build/run a vulnerable Ghost 6.19.0 environment. Dockerfile installs Ghost 6.19.0, downgrades jsonpath to 1.1.1 (and references static-eval 2.0.2 in docs), and configures Ghost to listen on port 2368. - Documentation: README.md and poc/CVE-2026-29053-POC.md explain the vulnerability, prerequisites (admin theme upload), and triggering steps. Notable observables: - Connect-back endpoint is embedded into the template payload (net.Socket().connect(PORT,'IP')). A sample hardcoded IP:port appears in the checked-in poc/page-rce.hbs but is intended to be replaced by exploit.py. - Build-time external endpoints in Dockerfile (gosu download, keys.openpgp.org) are for environment setup, not exploitation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.