Input Validation Flaw in Ghost Node.js CMS Affects Access Control
CVE-2026-105681
6.5MEDIUM
What is CVE-2026-105681?
In Ghost, a popular Node.js content management system, an input validation vulnerability existed that permitted unauthorized members to access comments not meant for them. This flaw affected versions from 5.9.0 to 6.44.1. It has been addressed in version 6.44.1, which resolves this issue by improving access control measures. Users are strongly advised to upgrade to the latest version to ensure the security of their content management system.
Affected Version(s)
Ghost >= 5.9.0, < 6.44.1
