Description
This module exploits a Remote Code Execution (RCE) vulnerability in Ghost CMS. Specifically crafted malicious themes can execute arbitrary code on the server running Ghost.
The affected versions include all releases from 0.7.2 up to and including 6.19.0. For versions 5.105.0-5.130.5 and 6.0.0-6.10.3, the module also leverages a 2FA bypass.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/multi/http/ghostcms/auth_rce_cve_2026_29053msf undefined(auth_rce_cve_2026_29053) > show actions ...actions...msf undefined(auth_rce_cve_2026_29053) > set ACTION < action-name >msf undefined(auth_rce_cve_2026_29053) > show options ...show and set options...msf undefined(auth_rce_cve_2026_29053) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub