CVE-2026-105675High· 7.5▾ TwilightGhost is a Node.js content management system. From 4.39.0 until 6.64.0, staff users with permission to view staff invites were able to discover the secret token of pending invites, including invites for roles with higher privileges than …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Ghost is a Node.js content management system. From 4.39.0 until 6.64.0, staff users with permission to view staff invites were able to discover the secret token of pending invites, including invites for roles with higher privileges than their own. This could allow a staff user to escalate their privileges by accepting a pending invite. This issue is fixed in version 6.64.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-105652Low· 3.1Ghost is a Node.js content management system
CVE-2026-104416High· 7.5Ghost from 4.39.0 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff users to view secret tokens of pending staff invites
CVE-2026-105679High· 7.3Ghost is a Node.js content management system
CVE-2026-105681Medium· 6.5Ghost is a Node.js content management system
CVE-2026-105677High· 7.2Ghost is a Node.js content management system
CVE-2026-105678Medium· 4.3Ghost is a Node.js content management system