CVE-2026-53947Medium· 5.3▾ SunlitGhost: Member existence leak via magic link sign-in response
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.2%
0.2% → 0.3%
A discrepancy in responses from the members signin endpoints made it possible for an unauthenticated attacker to determine whether a given email address belongs to a registered member of a Ghost site.
This vulnerability is present in Ghost from v5.18.0 up to v6.21.0.
v6.21.1 contains a fix for this issue.
For self-hosters using Docker, find Docker's official Ghost image here. Updating a Docker-based Ghost instance is documented here.
If your Ghost is a Ghost-CLI install see our documentation on updating it to the latest version here.
If you have any questions or comments about this advisory, email Ghost at [email protected].
ghost >= 5.18.0, < 6.21.1Upgrade to a patched release:
ghost 6.21.2Connected by shared product, vendor, weakness, or advisory.
CVE-2026-53948Medium· 5.4Ghost: File Upload Content-Type Spoofing
CVE-2026-53944Medium· 5.8Ghost: Private IP filtering bypass to make server-side requests to internal services
CVE-2026-53945Medium· 4.0Ghost: Server-side request forgery via DNS rebinding in external request handling
CVE-2026-53946Medium· 5.4Ghost: Mobiledoc image-size fetch SSRF
CVE-2026-70595Medium· 4.0Ghost is a Node.js content management system
CVE-2026-70596Medium· 4.3Ghost is a Node.js content management system