Skip to content
cortech.online
← Mythos
revealed · new_project

tryghost/ghost CVE-2026-26980: sql-injection

Daily Mythos tracker. Newly revealed CVE. New project added. 2128 total disclosed.

Two identifiers landed on 2026-06-03, both assigned to a single project and both classified as SQL injection: tryghost/ghost makes its first appearance in the Mythos corpus. The cumulative totals stand at 2128 disclosed, 1725 acknowledged, 414 patched, and 448 CVEs/GHSAs published.

tryghost/ghost — SQL injection

CVE-2026-26980 and its paired advisory GHSA-w52v-v783-gw97 are Ghost’s inaugural entries in the dashboard. Both identifiers carry a SQL-injection classification in the tryghost/ghost project; the dual filing — one CVE alongside one GitHub Security Advisory — is consistent with cross-database coordination on a single underlying finding. The new-project flag confirms this is the first time Mythos has surfaced findings in this codebase, with CVE-2026-26980 recorded as its first entry.

The day amounts to a small count but a meaningful debut: a widely deployed open-source CMS enters the tracked corpus with SQL-injection findings, a class that continues to surface across Mythos targets. With 448 CVEs and GHSAs published and 2128 findings disclosed in total, the 2026-06-03 additions are incremental in volume but extend the dataset’s reach into another major content platform.

Source: Anthropic’s Mythos dashboard at https://red.anthropic.com/2026/cvd/

Backfilled: reconstructed from the revealed_at timestamps in Anthropic’s CVD payload (as of 2026-08-26T18:55:53.809770Z), not published live on 2026-06-03.