MEDIUM 5.3 NVD
CVE-2026-103282
Ghost versions 0.5.0 before 6.23.0 contain a concurrency issue in the staff invitation acceptance mechanism that allows multiple accounts to be created from a s
Ghost versions 0.5.0 before 6.23.0 contain a concurrency issue in the staff invitation acceptance mechanism that allows multiple accounts to be created from a single invite token. Attackers can exploit this race condition by submitting concurrent requests with the same invitation token to create duplicate user accounts.
References
- https://github.com/TryGhost/Ghost/security/advisories/GHSA-vf9h-87xm-g767
- https://www.vulncheck.com/advisories/ghost-0.5.0-before-6.23.0-multiple-account-creation-v
This medium severity vulnerability with a CVSS score of 5.3 was published on 2026-10-01 via NVD.
vulnfeed aggregates 12641 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.