MEDIUM 5.3 GitHub
CVE-2026-59817
Ghost: Paid gift memberships obtainable at minimal cost via the donations feature
### Impact
A vulnerability in Ghost's public donation checkout flow allowed an unauthenticated attacker to obtain full paid gift memberships for a minimal payment. No customer or member data was exposed, and the issue could not be used to steal money from a site or its members.
### Vulnerable versions
This vulnerability is present in Ghost from [v6.27.0](https://github.com/TryGhost/Ghost/releases/tag/v6.27.0) up to [v6.43.1](https://github.com/TryGhost/Ghost/releases/tag/v6.43.1).
### Patche
Affected Products
- npm/ghost >= 6.27.0, < 6.44.0
References
- https://github.com/advisories/GHSA-xm43-3m56-w3wf
- https://github.com/TryGhost/Ghost/security/advisories/GHSA-xm43-3m56-w3wf
- https://nvd.nist.gov/vuln/detail/CVE-2026-59817
- https://github.com/TryGhost/Ghost/pull/28351
This medium severity vulnerability with a CVSS score of 5.3 was published on 2026-08-04 via GitHub. Affected: npm/ghost >= 6.27.0, < 6.44.0.
vulnfeed aggregates 9182 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.