Authorization Flaw in Ghost Node.js CMS by TryGhost
CVE-2026-105680

6.5MEDIUM

Key Information:

Vendor

Tryghost

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-105680?

The Ghost CMS, a popular Node.js content management system, contained an authorization error that permitted users with the Author role to delete articles and pages that they did not create. This vulnerability existed in versions 5.81.0 through 6.60.0 and was remedied in version 6.60.0. Maintain secure user roles and update your Ghost installation to the latest version to safeguard against this kind of vulnerability.

Affected Version(s)

Ghost >= 5.81.0, < 6.60.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.