Description
Ghost versions from 5.19.0 before 6.57.1 contain a cross-site request forgery vulnerability in the post feedback functionality that allows attackers to submit feedback on behalf of logged-in users. Attackers can craft a malicious link to the feedback page that automatically submits feedback when visited by authenticated members without their knowledge or consent.
Published: 2026-10-01
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Cross‑Site Request Forgery on logged‑in users
Action: Immediate Patch
AI Analysis

Impact

The vulnerability exists in Ghost’s post‑feedback component and allows an attacker to submit arbitrary feedback on behalf of authenticated members without their consent. The effect is to create or alter content that appears to come from legitimate users, which can be used for defacement, spreading misinformation, or tampering with user reputation. The weakness is a classic CSRF flaw, as identified by CWE‑352.

Affected Systems

Ghost content management system versions 5.19.0 through 6.57.0 are affected. The vulnerability is present in the core feedback module regardless of the site’s configuration, so any Ghost installation that has the feedback functionality enabled and is behind a user login is in scope.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate impact with effects limited to the confidentiality and integrity of user content. Because the attack requires a victim to be authenticated and to visit a crafted link, the practical exploitation window is narrower and the EPSS score is not available. The vulnerability is not listed in CISA’s KEV catalog, suggesting no widespread public exploitation has been reported. Nonetheless, an attacker can automate traffic to the feedback endpoint by hosting a malicious URL, and the impact could scale with the number of authenticated users targeted. Prompt remediation is advised to prevent potential abuse.

Generated by OpenCVE AI on October 1, 2026 at 14:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Ghost to version 6.57.1 or later, which contains the CSRF fix for the feedback endpoint
  • If upgrading is not immediately possible, enforce server‑side CSRF token validation for the feedback form and reject requests lacking a valid token
  • As a temporary measure, disable or restrict the feedback functionality for unauthenticated or low‑privilege users until a patch can be applied

Generated by OpenCVE AI on October 1, 2026 at 14:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description Ghost versions from 5.19.0 before 6.57.1 contain a cross-site request forgery vulnerability in the post feedback functionality that allows attackers to submit feedback on behalf of logged-in users. Attackers can craft a malicious link to the feedback page that automatically submits feedback when visited by authenticated members without their knowledge or consent.
Title Ghost 5.19.0 before 6.57.1 Cross-Site Request Forgery
First Time appeared Ghost
Ghost ghost
Weaknesses CWE-352
CPEs cpe:2.3:a:ghost:ghost:*:*:*:*:*:*:*:*
Vendors & Products Ghost
Ghost ghost
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T13:36:43.794Z

Reserved: 2026-09-30T10:59:26.443Z

Link: CVE-2026-103285

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-01T11:17:24.717

Modified: 2026-10-01T15:06:17.330

Link: CVE-2026-103285

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T14:45:10Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)