Impact
Ghost CMS versions 4.39.0 through 6.63.9 contain an information disclosure flaw in the Admin API that lets authorized staff see the secret tokens attached to pending staff invites. By obtaining these tokens, a staff user can accept an invitation designed for a higher‑privileged role, thereby elevating their own privileges. The root weakness is an improper access control that allows staff users to view data they should not have access to, classified under CWE‑203.
Affected Systems
Affected is Ghost CMS from TryGhost, specifically any deployment running Ghost 4.39.0, 5.x, or 6.x up to 6.63.9. These versions expose the Admin API endpoint that leaks invite tokens to any staff member with invite‑view permission.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.7, indicating high severity, but the EPSS score is not available so the exploitation probability cannot be quantified at this time. It is not listed in the CISA KEV catalog. The likely attack vector is an authenticated request to the Admin API endpoint made by a staff user with the appropriate permission; the attacker does not need to bypass authentication but merely requires the right privilege level to trigger the disclosure.
OpenCVE Enrichment