PT-2026-20787 · Ghost · Ghost
Nicholas Carlini
·
Published
2026-02-18
·
Updated
2026-04-19
·
CVE-2026-26980
CVSS v3.1
9.4
Critical
| AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Ghost versions 3.24.0 through 6.19.0
Description
Ghost is a Node.js content management system. A blind SQL injection exists in the Content API, specifically within the '/ghost/api/content' endpoint. This flaw allows unauthenticated attackers to perform arbitrary reads from the database, which can lead to the theft of admin API keys and full administrative account takeover.
Recommendations
Update to version 6.19.1.
As a temporary mitigation, use a reverse proxy or WAF rule to block Content API requests containing
slug%3A%5B or slug:[ in the query string filter parameter.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ghost