Two identifiers landed on 2026-06-03, both assigned to a single project and both classified as SQL injection: tryghost/ghost makes its first appearance in the Mythos corpus. The cumulative totals stand at 2128 disclosed, 1725 acknowledged, 414 patched, and 448 CVEs/GHSAs published.
tryghost/ghost — SQL injection
CVE-2026-26980 and its paired advisory GHSA-w52v-v783-gw97 are Ghost’s inaugural entries in the dashboard. Both identifiers carry a SQL-injection classification in the tryghost/ghost project; the dual filing — one CVE alongside one GitHub Security Advisory — is consistent with cross-database coordination on a single underlying finding. The new-project flag confirms this is the first time Mythos has surfaced findings in this codebase, with CVE-2026-26980 recorded as its first entry.
The day amounts to a small count but a meaningful debut: a widely deployed open-source CMS enters the tracked corpus with SQL-injection findings, a class that continues to surface across Mythos targets. With 448 CVEs and GHSAs published and 2128 findings disclosed in total, the 2026-06-03 additions are incremental in volume but extend the dataset’s reach into another major content platform.
Source: Anthropic’s Mythos dashboard at https://red.anthropic.com/2026/cvd/
Backfilled: reconstructed from the revealed_at timestamps in Anthropic’s CVD payload (as of 2026-08-26T18:55:53.809770Z), not published live on 2026-06-03.