github.com
https://github.com/TryGhost/Ghost CVE-2026-70589
MEDIUM
Ghost: Archived Offers can be Redeemed
Record summary
CVE-2026-70589 has a selected CVSS score of 4.8 (medium).
Description
Ghost is a Node.js content management system. From 4.22.0 until 6.54.1, a missing validation check allowed users to redeem subscription offers that were no longer active. This issue is fixed in version 6.54.1.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 5, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | >= 4.22.0, < 6.54.1 | affected | |
ghostBrowse npm / ghost | GitHub Advisory | 4.22.0 to < 6.54.1 · Fixed in 6.54.1 | affected |
References
3github.com
https://github.com/TryGhost/Ghost/commit/d91c0fc52dfc987d71a9803dbcbe6447d21b92fb github.comConfirmation
https://github.com/TryGhost/Ghost/security/advisories/GHSA-4wx2-7gvj-qfq3