Description
Ghost (npm package 'ghost') versions from 3.23.0 up to, but not including, 6.23.0 expose API keys to users with low-privilege staff accounts. An authenticated low-privilege staff user can read API keys returned by the Admin API, which are intended to be available only to higher-privileged users.
Published: 2026-10-01
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized disclosure of API keys to low‑privilege staff users
Action: Apply Patch
AI Analysis

Impact

The vulnerability lies in the Ghost CMS API, allowing authenticated staff users with low privileges to retrieve API keys normally restricted to higher‑level roles. The exposed keys can be used to access external services or cloud resources, leading to potential unauthorized access or data exfiltration. This flaw represents a moderate data‑exposure weakness (CWE‑201).

Affected Systems

Ghost CMS versions starting at 3.23.0 and up to, but not including, 6.23.0 are affected. These versions expose sensitive credentials via the Admin API. The affected product is the Ghost CMS package from the TryGhost vendor.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited public exploitation. The likely attack vector requires an authenticated low‑privilege staff account that can access the Admin API; an attacker must first compromise or obtain valid credentials for such a role, after which the exposed keys can be retrieved and misused.

Generated by OpenCVE AI on October 1, 2026 at 14:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Ghost CMS to version 6.23.0 or later
  • If an upgrade is not yet possible, re‑evaluate role permissions so that low‑privilege staff cannot invoke the Admin API endpoints that return API keys
  • Implement monitoring or logging of Admin API calls to detect unauthorized key disclosures

Generated by OpenCVE AI on October 1, 2026 at 14:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description Ghost (npm package 'ghost') versions from 3.23.0 up to, but not including, 6.23.0 expose API keys to users with low-privilege staff accounts. An authenticated low-privilege staff user can read API keys returned by the Admin API, which are intended to be available only to higher-privileged users.
Title Ghost 3.23.0 before 6.23.0 API Key Exposure via Admin API
First Time appeared Ghost
Ghost ghost
Weaknesses CWE-201
CPEs cpe:2.3:a:ghost:ghost:*:*:*:*:*:*:*:*
Vendors & Products Ghost
Ghost ghost
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T13:36:16.839Z

Reserved: 2026-09-30T10:59:00.639Z

Link: CVE-2026-103281

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-01T11:17:24.073

Modified: 2026-10-01T15:06:17.330

Link: CVE-2026-103281

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T14:45:10Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data