HIGH 7.5 NVD
CVE-2026-105675
Ghost is a Node.js content management system. From 4.39.0 until 6.64.0, staff users with permission to view staff invites were able to discover the secret token
Ghost is a Node.js content management system. From 4.39.0 until 6.64.0, staff users with permission to view staff invites were able to discover the secret token of pending invites, including invites for roles with higher privileges than their own. This could allow a staff user to escalate their privileges by accepting a pending invite. This issue is fixed in version 6.64.0.
References
- https://github.com/TryGhost/Ghost/commit/4fb587e4d49667f929b87f7d6a873ae5e9cc087f
- https://github.com/TryGhost/Ghost/pull/30760
- https://github.com/TryGhost/Ghost/releases/tag/v6.64.0
- https://github.com/TryGhost/Ghost/security/advisories/GHSA-v6q3-xqxm-6f5v
This high severity vulnerability with a CVSS score of 7.5 was published on 2026-10-05 via NVD.
vulnfeed aggregates 7729 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.