---
id: CVE-2026-105678
title: Ghost is a Node.js content management system
summary: >-
  Ghost is a Node.js content management system. From 0.5.0 until 6.64.0, staff
  users with the Editor or Super Editor role were able to assign their own role
  to Author and Contributor users, despite not having permission to assign that
  role…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-269
  - CWE-863
vendor: TryGhost
product: Ghost
affected:
  - 'Ghost >= 0.5.0, < 6.64.0'
published: '2026-10-05'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T20:17:14.913'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105678'
references:
  - url: >-
      https://github.com/TryGhost/Ghost/commit/99c5642b9bb481df4811a004a6f19d6143ed9aaf
    label: security-advisories@github.com
  - url: 'https://github.com/TryGhost/Ghost/issues/30764'
    label: security-advisories@github.com
  - url: 'https://github.com/TryGhost/Ghost/releases/tag/v6.64.0'
    label: security-advisories@github.com
  - url: 'https://github.com/TryGhost/Ghost/security/advisories/GHSA-4pvx-fwjj-8gpc'
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-05T20:32:56.647Z'
---

## Overview

Ghost is a Node.js content management system. From 0.5.0 until 6.64.0, staff users with the Editor or Super Editor role were able to assign their own role to Author and Contributor users, despite not having permission to assign that role. This issue is fixed in version 6.64.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
