BIT-ghost-2026-70594

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/ghost/BIT-ghost-2026-70594.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-ghost-2026-70594
Aliases
Published
2026-08-17T05:41:04.504Z
Modified
2026-08-17T08:10:58.516113186Z
Summary
Ghost: Session Fixation in Ghost Admin
Details

Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions on login which could have allowed for session fixation attacks. Successful exploitation would have required another vulnerability on the same domain where Ghost Admin was hosted. This issue is fixed in version 6.54.1.

Database specific
{
    "severity": "Medium",
    "cpes": [
        "cpe:2.3:a:ghost:ghost:*:*:*:*:*:node.js:*:*"
    ]
}
References

Affected packages

Bitnami / ghost

Package

Name
ghost
Purl
pkg:bitnami/ghost

Severity

  • 6.7 (Medium) CVSS_V3 - CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
2.2.0
Fixed
6.54.1

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/ghost/BIT-ghost-2026-70594.json"