{"id":"CVE-2026-105681","title":"Ghost is a Node.js content management system","summary":"Ghost is a Node.js content management system. From 5.9.0 until 6.44.1, an input validation issue allowed members to access comments they were not authorized to access. This issue is fixed in version 6.44.1.","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-943"],"vendor":"TryGhost","product":"Ghost","affected":["Ghost >= 5.9.0, < 6.44.1"],"published":"2026-10-05","updated":"2026-10-05","sourceUpdated":"2026-10-05T20:17:16.320","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105681","references":[{"url":"https://github.com/TryGhost/Ghost/commit/405c2623ff9060295d4a87d3a0eb4ef766c8d2d3","label":"security-advisories@github.com"},{"url":"https://github.com/TryGhost/Ghost/pull/28297","label":"security-advisories@github.com"},{"url":"https://github.com/TryGhost/Ghost/releases/tag/v6.44.1","label":"security-advisories@github.com"},{"url":"https://github.com/TryGhost/Ghost/security/advisories/GHSA-6q6j-f24j-p477","label":"security-advisories@github.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-05T20:32:56.648Z","slug":"CVE-2026-105681","body":"## Overview\n\nGhost is a Node.js content management system. From 5.9.0 until 6.44.1, an input validation issue allowed members to access comments they were not authorized to access. This issue is fixed in version 6.44.1.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}