← Back

CVE-2026-22595

nvd nist
Published: Jan 10, 2026Modified: Jan 15, 2026

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Exploitability: 2.8 / Impact: 5.2
Source: security-advisories@github.com (Secondary)

Description

Ghost is a Node.js content management system. In versions 5.121.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's handling of Staff Token authentication allowed certain endpoints to be accessed that were only intended to be accessible via Staff Session authentication. External systems that have been authenticated via Staff Tokens for Admin/Owner-role users would have had access to these endpoints. This issue has been patched in versions 5.130.6 and 6.11.0.

Affected (2)

Products: Ghost: Ghost
1 product
Ghost
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Ghost
From 5.121.0 to 5.130.6
From 6.0.0 to 6.11.0

References (3)

Timeline

No history available yet.