An input validation issue allowed members to access comments they were not authorized to access.
This vulnerability is present in Ghost from v5.9.0 up to v6.44.1.
v6.44.1 contains a fix for this issue.
For self-hosters using Docker, find Docker's official Ghost image here. Updating a Docker-based Ghost instance is documented here.
If your Ghost is a Ghost-CLI install see our documentation on updating it to the latest version here.
Ghost thanks Himanshu Anand (@anand_himanshu) for disclosing this vulnerability responsibly.
If you have any questions or comments about this advisory, email us at security@ghost.org.
{
"cwe_ids": [
"CWE-943"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-07T16:18:00Z",
"nvd_published_at": "2026-10-05T20:17:16Z",
"severity": "MODERATE"
}