GHSA-m47h-25hm-c3r9HighCVSS 8.8

Ghost versions before 6.62.0 contain an authentication bypass vulnerability that allows suspended...

Published
October 1, 2026
Last Modified
October 1, 2026

🔗 CVE IDs covered (1)

📋 Description

Ghost versions before 6.62.0 contain an authentication bypass vulnerability that allows suspended staff users to reactivate their accounts through self-service password reset. Attackers with suspended staff credentials can perform password reset operations to regain active account access and restore their original privileges.

🔗 References (4)