MEDIUM 4.3 NVD
CVE-2026-70596
Ghost is a Node.js content management system. From 4.9.0 until 6.54.1, an input validation issue allowed any staff user to create a post with content in feature
Ghost is a Node.js content management system. From 4.9.0 until 6.54.1, an input validation issue allowed any staff user to create a post with content in feature_image_caption that could be used to hijack another staff user's Ghost Admin session, resulting in privilege escalation. This issue is fixed in 6.54.1.
References
- https://github.com/TryGhost/Ghost/commit/a8bea3a4ceec4c852b880f4885119453c3d8588e
- https://github.com/TryGhost/Ghost/pull/29635
- https://github.com/TryGhost/Ghost/releases/tag/v6.54.1
- https://github.com/TryGhost/Ghost/security/advisories/GHSA-pr22-p9rp-2cqv
This medium severity vulnerability with a CVSS score of 4.3 was published on 2026-08-05 via NVD.
vulnfeed aggregates 9316 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.