github.com
https://github.com/TryGhost/Ghost CVE-2026-22595
HIGH
Ghost has Staff Token permission bypass
Record summary
CVE-2026-22595 has a selected CVSS score of 8.1 (high).
Description
Ghost is a Node.js content management system. In versions 5.121.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's handling of Staff Token authentication allowed certain endpoints to be accessed that were only intended to be accessible via Staff Session authentication. External systems that have been authenticated via Staff Tokens for Admin/Owner-role users would have had access to these endpoints. This issue has been patched in versions 5.130.6 and 6.11.0.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 12, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | >= 6.0.0, < 6.11.0 | affected | |
| >= 5.121.0, < 5.130.6 | affected | ||
ghostBrowse npm / ghost | GitHub Advisory | 6.0.0 to < 6.11.0 · Fixed in 6.11.0 | affected |
| 5.105.0 to < 5.130.6 · Fixed in 5.130.6 | affected |
References
5github.com
https://github.com/TryGhost/Ghost/commit/9513d2a35c21067127ce8192443d8919ddcefcc8 github.com
https://github.com/TryGhost/Ghost/commit/c3017f81a5387b253a7b8c1ba1959d430ee536a3 github.comConfirmation
https://github.com/TryGhost/Ghost/security/advisories/GHSA-9xg7-mwmp-xmjx nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-22595