github.com
https://github.com/TryGhost/Ghost CVE-2026-70594
MEDIUM
Ghost: Session Fixation in Ghost Admin
Record summary
CVE-2026-70594 has a selected CVSS score of 6.7 (medium).
Description
Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions on login which could have allowed for session fixation attacks. Successful exploitation would have required another vulnerability on the same domain where Ghost Admin was hosted. This issue is fixed in version 6.54.1.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 5, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | >= 2.2.0, < 6.54.1 | affected | |
ghostBrowse npm / ghost | GitHub Advisory | 2.2.0 to < 6.54.1 · Fixed in 6.54.1 | affected |
References
5github.com
https://github.com/TryGhost/Ghost/commit/6b1c85c30dd0bacb4d5ffe64fc675ac9342d800c github.com
https://github.com/TryGhost/Ghost/pull/29634 github.com
https://github.com/TryGhost/Ghost/releases/tag/v6.54.1 github.comConfirmation
https://github.com/TryGhost/Ghost/security/advisories/GHSA-7mpp-r37j-x5wh