Description
Ghost from version 0.8.0 before 6.23.0 contains an information disclosure vulnerability in its setup endpoint: the endpoint responds to unauthenticated requests with the site owner's email address, allowing any remote visitor to obtain it.
Published: 2026-10-01
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

Ghost from version 0.8.0 through 6.22.x contains an information disclosure flaw. The setup endpoint, which should be secured or removed, will return the site owner's email address to anyone who sends an unauthenticated request. An attacker can use the returned email address for targeted phishing, social engineering, or as a reconnaissance step for further attacks. The vulnerability does not provide code execution or direct access to data, but it compromises the confidentiality of the site owner's contact information.

Affected Systems

The affected product is Ghost, maintained by TryGhost. Vulnerable releases include Ghost 0.8.0 up to, but not including, version 6.23.0. Systems running any version in this range expose the email address via the setup endpoint.

Risk and Exploitability

The CVSS score of 6.9 classifies this issue as a medium severity flaw. The EPSS score is not available, so the likelihood of exploitation in the wild cannot be precisely measured, but the vulnerability is publicly documented and the impacted endpoint is reachable over the network. The flaw is listed as not in the CISA KEV catalog, indicating no known active exploitation at the time of the analysis. Attackers can obtain the disclosed email address by crafting simple HTTP requests to the setup endpoint without authentication, making the exploit trivial for automated scanners or custom scripts.

Generated by OpenCVE AI on October 1, 2026 at 14:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Ghost to version 6.23.0 or later, which removes the information disclosure from the setup endpoint.
  • If an upgrade cannot be performed immediately, limit access to the setup endpoint by configuring network or application firewalls to block unauthenticated requests, or by changing permissions so only trusted administrators can reach it.
  • Monitor web server logs for repeated requests to the /setup endpoint and investigate any abnormal traffic patterns that could indicate reconnaissance attempts.

Generated by OpenCVE AI on October 1, 2026 at 14:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description Ghost from version 0.8.0 before 6.23.0 contains an information disclosure vulnerability in its setup endpoint: the endpoint responds to unauthenticated requests with the site owner's email address, allowing any remote visitor to obtain it.
Title Ghost 0.8.0 before 6.23.0 Information Disclosure via Setup Endpoint
First Time appeared Ghost
Ghost ghost
Weaknesses CWE-201
CPEs cpe:2.3:a:ghost:ghost:*:*:*:*:*:*:*:*
Vendors & Products Ghost
Ghost ghost
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T13:32:45.073Z

Reserved: 2026-09-30T10:59:00.639Z

Link: CVE-2026-103280

cve-icon Vulnrichment

Updated: 2026-10-01T13:32:36.647Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T11:17:23.907

Modified: 2026-10-01T15:06:17.330

Link: CVE-2026-103280

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T14:45:10Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data