GHSA-crq6-86x9-65hjMediumCVSS 5.4

Ghost (npm package 'ghost') versions from 3.23.0 up to, but not including, 6.23.0 expose API keys...

Published
October 1, 2026
Last Modified
October 1, 2026

🔗 CVE IDs covered (1)

📋 Description

Ghost (npm package 'ghost') versions from 3.23.0 up to, but not including, 6.23.0 expose API keys to users with low-privilege staff accounts. An authenticated low-privilege staff user can read API keys returned by the Admin API, which are intended to be available only to higher-privileged users.

🔗 References (4)