Remote Code Execution (RCE) in Ghost CMS (CVE-2026-29053): A Transitive Dependency Wreaks Havoc
Blog post from Endor Labs
A significant remote code execution (RCE) vulnerability, identified as CVE-2026-29053, was discovered in Ghost CMS, a widely used Node.js content management system. This vulnerability, now patched in version 6.19.1, allowed attackers to execute arbitrary JavaScript code by manipulating themes and persuading administrators to install them. The issue stemmed from the use of the jsonpath package, which relied on static-eval to interpret potentially malicious JSONPath expressions in Handlebars templates. Originally, Ghost CMS was using outdated versions of these packages, which were not suitable for handling untrusted input, enabling attackers to craft code execution exploits through prototype chain manipulation. Although the Ghost team initially considered upgrading the problematic dependencies, they ultimately opted to eliminate the dependency on jsonpath entirely, implementing a custom solution that safely retrieves data from JSON structures without risking code execution. This decision highlights the importance of removing dependencies that introduce serious security risks and crafting purpose-built alternatives tailored to specific application needs.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.