Node.js Content Management System Vulnerability in Ghost by TryGhost
CVE-2026-70589

4.8MEDIUM

Key Information:

Vendor

Tryghost

Status
Vendor
CVE Published:
4 August 2026

What is CVE-2026-70589?

Ghost, a popular Node.js content management system, suffers from a vulnerability that allows users to take advantage of expired subscription offers due to inadequate validation checks. This flaw is prevalent in versions ranging from 4.22.0 to 6.54.1. The issue has been addressed in version 6.54.1, ensuring proper validation mechanisms are in place to prevent abuse.

Affected Version(s)

Ghost >= 4.22.0, < 6.54.1

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.