Impact
Ghost versions 5.3.0 through 6.57.9 fail to properly enforce access controls on comments in private mode, allowing unauthenticated visitors to read comments that should be restricted. The flaw is an access control weakness (CWE‑862) that results in confidentiality violations by exposing user commentary; no code execution or other impacts are described.
Affected Systems
The affected product is Ghost, a popular open‑source publishing platform. Versions from 5.3.0 up to, but not including, 6.58.0 are vulnerable. These versions are used by many blogs and small media sites. The vendor associated with the CNAs is TryGhost.
Risk and Exploitability
The CVSS v3.1 score of 6.9 indicates a moderate severity, with likely exploitation via normal HTTP traffic to the public site. The EPSS score is not available, so we cannot quantify current exploit probability. The vulnerability is not listed in the CISA KEV catalog. Attackers can simply access the comment URLs on a public Ghost installation to retrieve private discussions, and because no authentication is required, the attack can be performed from anywhere on the internet.
OpenCVE Enrichment