Impact
Ghost content API versions from 2.10.0 through just before 6.63.0 allow an attacker who does not need to authenticate to discover which users are registered as staff. By sending crafted requests to the API, an attacker can observe differences in metadata responses and use those discrepancies to enumerate staff members and extract sensitive information. This can expose personal data, contact details, or other confidential information belonging to staff, thereby compromising the confidentiality of the site’s user base. The weakness is a common identifier for information disclosure vulnerabilities, CWE-203.
Affected Systems
Vendors affected are TryGhost, product Ghost. Anyone running Ghost version 2.10.0, 3.x, 4.x, 5.x or 6.x prior to 6.63.0 is potentially vulnerable. The vulnerable range includes every release within that bracket; no specific minor patches are listed that address the issue.
Risk and Exploitability
The CVSS score of 8.7 rates this as high severity, reflecting significant impact if exploited. The EPSS score is not available, but the vulnerability is listed as not currently part of the CISA KEV catalog, indicating no confirmed public exploitation. The likely attack vector is a remote unauthenticated API call over the network, as the flaw requires no credentials. Because the attacker can trigger enumeration without any need to login, the logistical barrier to exploit is minimal. All evidence for exploitation derives from the official vulnerability advisory and the impact description; no additional details are present.
OpenCVE Enrichment