Information Exposure Affecting ghost package, versions <6.54.1


Severity

Recommended
0.0
low
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.2% (10th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-GHOST-18610057
  • published11 Aug 2026
  • disclosed4 Aug 2026
  • creditChapman Schleiss

Introduced: 4 Aug 2026

NewCVE-2026-70590  (opens in a new tab)
CWE-200  (opens in a new tab)

How to fix?

Upgrade ghost to version 6.54.1 or higher.

Overview

ghost is a publishing platform

Affected versions of this package are vulnerable to Information Exposure via the posts and pages browse and export filtering paths in PostsService, PostsExporter, and the posts/pages admin controllers. An attacker can leak other staff users’ password hashes by sending an admin API request with a crafted filter such as authors.password:abcd on /posts, /posts/export, or /pages.

Notes

  • The leak only applies to staff-admin requests that use the admin API browse/export filter syntax on posts or pages; the maintainer advisory says the hashes were exposed to any staff-level user.

Workarounds

CVSS Base Scores

version 4.0
version 3.1