CVE-2026-70590Medium· 4.8▾ SunlitGhost is a Node.js content management system. Prior to 6.54.1, any staff-level user was able to leak the hashed passwords of other staff users through the Ghost Admin API. An offline password-guessing attack against the hashes could lead…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 26.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 5.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
Last analysed / modified upstream
Ghost is a Node.js content management system. Prior to 6.54.1, any staff-level user was able to leak the hashed passwords of other staff users through the Ghost Admin API. An offline password-guessing attack against the hashes could lead to account takeover if successful, but Device Verification should have prevented an attacker from logging in with a recovered password. Depending on the database used, leaked hashes may not have had the correct casing for all characters, increasing the difficulty of a password-guessing attack. This issue is fixed in version 6.54.1.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
ghost < 6.54.1Patched in:
ghost 6.54.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-70596Medium· 4.3Ghost is a Node.js content management system
CVE-2026-53949Medium· 5.3Ghost Content API filter bypass reveals private fields
CVE-2026-70593Medium· 6.6Ghost is a Node.js content management system
CVE-2026-70594Medium· 6.7Ghost is a Node.js content management system
CVE-2026-70588Medium· 5.0Ghost is a Node.js content management system
CVE-2026-70591Medium· 4.1Ghost is a Node.js content management system