MEDIUM 6.5 NVD
CVE-2026-105681
Ghost is a Node.js content management system. From 5.9.0 until 6.44.1, an input validation issue allowed members to access comments they were not authorized to
Ghost is a Node.js content management system. From 5.9.0 until 6.44.1, an input validation issue allowed members to access comments they were not authorized to access. This issue is fixed in version 6.44.1.
References
- https://github.com/TryGhost/Ghost/commit/405c2623ff9060295d4a87d3a0eb4ef766c8d2d3
- https://github.com/TryGhost/Ghost/pull/28297
- https://github.com/TryGhost/Ghost/releases/tag/v6.44.1
- https://github.com/TryGhost/Ghost/security/advisories/GHSA-6q6j-f24j-p477
This medium severity vulnerability with a CVSS score of 6.5 was published on 2026-10-05 via NVD.
vulnfeed aggregates 7729 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.