CVE-2026-70596Medium· 4.3▾ SunlitGhost is a Node.js content management system. From 4.9.0 until 6.54.1, an input validation issue allowed any staff user to create a post with content in feature_image_caption that could be used to hijack another staff user's Ghost Admin …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 6.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
Last analysed / modified upstream
Ghost is a Node.js content management system. From 4.9.0 until 6.54.1, an input validation issue allowed any staff user to create a post with content in feature_image_caption that could be used to hijack another staff user's Ghost Admin session, resulting in privilege escalation. This issue is fixed in 6.54.1.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
ghost >= 4.9.0, < 6.54.1Patched in:
ghost 6.54.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-70588Medium· 5.0Ghost is a Node.js content management system
CVE-2026-70593Medium· 6.6Ghost is a Node.js content management system
CVE-2026-70594Medium· 6.7Ghost is a Node.js content management system
CVE-2026-70590Medium· 4.8Ghost is a Node.js content management system
CVE-2026-70591Medium· 4.1Ghost is a Node.js content management system
CVE-2026-70592Medium· 5.5Ghost is a Node.js content management system