User Information Disclosure in Node.js Content Management System by Ghost
CVE-2026-105652

3.1LOW

Key Information:

Vendor

Tryghost

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-105652?

A security vulnerability exists in Ghost, a Node.js content management system, where staff-level users can determine the relative order of other staff members' hashed passwords. This vulnerability arises between versions 0.7.2 and 6.63.0. Although it does not expose actual password hashes or provide a straightforward method to recover passwords, it can lead to insights into user account structures that may be exploited in social engineering attacks. The issue has been addressed in version 6.64.0, and users are strongly advised to update to this version to mitigate any potential risks.

Affected Version(s)

Ghost >= 0.7.2, < 6.64.0

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.