Impact
The staff invitation flow in Ghost contains a race condition that lets many user accounts be created from one invite token. By sending two or more concurrent requests with the same token, an attacker can trigger the account‑creation routine repeatedly. Each resulting account has the privileges granted to the inviting staff member, allowing an attacker to gain unintended accounts and possibly elevate privileges. This is a classic concurrency bug classified by CWE‑362.
Affected Systems
The flaw exists in Ghost CMS version 0.5.0 and every release up to, but not including, 6.23.0. Any organization running those versions is vulnerable; the problem resides in the staff invitation acceptance endpoint of the web API.
Risk and Exploitability
The CVSS score is 5.3, indicating moderate severity. No EPSS score is available and the issue is not listed in the CISA KEV catalog, so there is no confirmed public exploitation yet. An adversary would need the ability to issue web requests to the application and must send them almost simultaneously to trigger the race condition. Crafting such a request pattern is straightforward with a small script, meaning an attacker can engineer the attack quickly. Although it does not lead to remote code execution, it provides unauthorized account creation and can aid in privilege escalation.
OpenCVE Enrichment