Sceawere
Vulnerability Detail
CVE-2026-105675UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Ghost Privilege Escalation via Invites
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 1d ago
- Vendor
- TryGhost
- Product
- Ghost
- Attack Type
- CWE-203: Observable Discrepancy
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
Ghost is a Node.js content management system. From 4.39.0 until 6.64.0, staff users with permission to view staff invites were able to discover the secret token of pending invites, including invites for roles with higher privileges than their own. This could allow a staff user to escalate their privileges by accepting a pending invite. This issue is fixed in version 6.64.0.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-10-05T20:17:14.367Z",
"pubdate": "2026-10-05T20:17:14.367Z",
"executiveSummary": "A privilege escalation vulnerability exists in Ghost, a Node.js content management system, stemming from improper access control in the staff invite management module.\nThe vulnerability allows a staff user with restricted permissions to access the secret tokens of pending invitations intended for other users, including those with higher-level administrative privileges.\nBy capturing these secret tokens, an authenticated attacker can perform an account takeover or escalate their internal role by accepting the pending invitations.\nThe flaw affects versions 4.39.0 through 6.64.0 and poses a significant risk to the integrity and confidentiality of the administrative backend.\nSuccessful exploitation requires the attacker to hold an existing staff account on the Ghost instance and possess the 'view staff invites' permission.\nThe vulnerability is primarily rooted in an authorization bypass where the application fails to validate the scope of the requester against the privilege level of the invite being retrieved.\nThe impact includes unauthorized elevation of privileges, potential full system compromise, and unauthorized administrative actions within the Ghost instance.\nDefensive posture requires immediate patching to the fixed version 6.64.0.",
"technicalDetails": "The vulnerability is categorized as an Insecure Direct Object Reference (IDOR) combined with improper authorization checks within the Ghost invite management API.\nThe root cause lies in the application's backend logic for processing requests related to pending staff invitations. Specifically, the API endpoint responsible for listing or retrieving invitation details fails to adequately verify if the requesting user has the appropriate authorization level to view specific, high-privilege invite metadata.\nAffected versions include any deployment of Ghost from 4.39.0 up to and including 6.64.0.\nThe attack flow begins when an authenticated staff member, who already possesses the legitimate permission to view the staff invite list, executes a query to the backend API to retrieve pending invitations. Because the backend fails to apply strict Role-Based Access Control (RBAC) filtering on the response object, the API returns the sensitive 'secret token' associated with every pending invitation, regardless of the role designated for that invite.\nAn attacker can monitor the API response for invitations directed toward administrative or 'Owner' roles. Upon discovering a token for a high-privilege invite, the attacker can then invoke the invitation acceptance flow provided by the Ghost application, typically handled via a specific endpoint that consumes the secret token to bind an account or upgrade an existing profile.\nBy submitting the discovered secret token, the attacker validates their identity against the invitation parameters. If successful, the system updates the attacker's account privileges to match those defined in the captured invitation. This effectively bypasses the intended separation of duties and access control policies established by the Ghost administrator.\nThis vulnerability is particularly dangerous because the API exposure provides an attacker with the necessary credentials (the secret token) to bypass standard authentication workflows, allowing for persistent privilege escalation. Post-exploitation, the attacker gains the operational capabilities associated with the elevated role, which may include site configuration, user management, and content deletion, depending on the role obtained via the intercepted invite.\nThe lack of server-side validation during the retrieval of invitation data allows the information disclosure of tokens that should otherwise remain private until the intended recipient interacts with the invite link via a secure channel."
}