Impact
Ghost versions prior to 6.62.0 allow users to specify an arbitrary email address when accepting a staff invite, effectively bypassing the intended invitation flow. This flaw enables attackers who have acquired leaked invite tokens to create accounts with any chosen email address, or it allows legitimate invitees to end up registered with an unintended email provider. The result is unauthorized access to the application with staff or administrative privileges, exposing the system to potential data theft, manipulation, or further compromise. This weakness aligns with CWE-807, a failure to enforce proper permission checks during authentication.
Affected Systems
The vulnerability affects Ghost deployments by TryGhost. All Ghost releases before 6.62.0, including the 0.5.0 release, are impacted. Users running these older versions are at risk until they update to a patched release.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, but the absence of an EPSS score suggests that widespread exploitation is not yet documented. The vulnerability is not included in CISA’s KEV catalog. Attackers would need a valid staff invite token, which may be leaked or compromised, and can then execute the bypass from a remote web interface. Because the flaw allows direct account creation without legitimate verification, the impact is significant for the scopes that rely on staff invites for privileged access.
OpenCVE Enrichment