Input validation error in Ghost - CVE-2026-29053
Published: April 27, 2026
Ghost
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper input validation in the theme installation and processing functionality when handling specially crafted themes. A remote privileged user can install a specially crafted malicious theme to execute arbitrary code.
User interaction is required to install the crafted theme.