Impact
The flaw lies in an input validation problem within the comments subsystem of Ghost CMS. It permits authenticated members to fetch and view comments that are otherwise protected, thereby leaking private discussion content. No code execution or denial of service is possible – the violation is limited to unauthorized read access.
Affected Systems
TryGhost Ghost CMS versions 5.9.0 through 6.44.0 are vulnerable. The fix is included in version 6.44.1 and later. Ghost releases earlier than 5.9.0 are not affected by this issue.
Risk and Exploitability
With a CVSS score of 7.1 the vulnerability is regarded as high severity. EPSS information is unavailable and the flaw is not listed in CISA’s KEV catalog, indicating no recorded widespread exploitation. Attack requires only that an adversary obtain valid credentials or compromise an existing account; after authentication they can query comment data that is not meant for their role. The threat surface is therefore confined to insider misuse or compromised accounts, but it can still expose sensitive user information.
OpenCVE Enrichment