User Information Disclosure in Node.js Content Management System by Ghost
CVE-2026-105652
3.1LOW
What is CVE-2026-105652?
A security vulnerability exists in Ghost, a Node.js content management system, where staff-level users can determine the relative order of other staff members' hashed passwords. This vulnerability arises between versions 0.7.2 and 6.63.0. Although it does not expose actual password hashes or provide a straightforward method to recover passwords, it can lead to insights into user account structures that may be exploited in social engineering attacks. The issue has been addressed in version 6.64.0, and users are strongly advised to update to this version to mitigate any potential risks.
Affected Version(s)
Ghost >= 0.7.2, < 6.64.0
