GHSA-3qxh-9f4j-4rwpMediumCVSS 4.3

Ghost versions 4.3.0 before 6.58.0 contain an authentication bypass vulnerability where lower...

Published
October 1, 2026
Last Modified
October 1, 2026

🔗 CVE IDs covered (1)

📋 Description

Ghost versions 4.3.0 before 6.58.0 contain an authentication bypass vulnerability where lower-privilege staff users can use staff tokens to bypass post editing restrictions. Attackers with staff credentials can leverage tokens to edit posts beyond their assigned privilege level.

🔗 References (4)