Impact
The vulnerability lies in the Ghost CMS API, allowing authenticated staff users with low privileges to retrieve API keys normally restricted to higher‑level roles. The exposed keys can be used to access external services or cloud resources, leading to potential unauthorized access or data exfiltration. This flaw represents a moderate data‑exposure weakness (CWE‑201).
Affected Systems
Ghost CMS versions starting at 3.23.0 and up to, but not including, 6.23.0 are affected. These versions expose sensitive credentials via the Admin API. The affected product is the Ghost CMS package from the TryGhost vendor.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited public exploitation. The likely attack vector requires an authenticated low‑privilege staff account that can access the Admin API; an attacker must first compromise or obtain valid credentials for such a role, after which the exposed keys can be retrieved and misused.
OpenCVE Enrichment