CVE-2026-105681 MEDIUM

CVE-2026-105681: Ghost: Authorization Bypass in Comments Feature

Vendor Tryghost
Product Ghost
Weakness CWE-943
Published October 5, 2026
Last update October 5, 2026

CVSS base score

6.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

What the vulnerability does

01Description

Ghost is a Node.js content management system. From 5.9.0 until 6.44.1, an input validation issue allowed members to access comments they were not authorized to access. This issue is fixed in version 6.44.1.

Key dates

02Disclosure timeline

October 5, 2026 CVE published