top of page
perceptive_background_267k.jpg

Ghost is a Node.js content management system. In versions 5.121.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's handling of Staff Token a…

Published:

9 January 2026 at 23:00:00

Alert date:

10 January 2026 at 13:10:58

Source:

nvd.nist.gov

Click to open the original link from this advisory

A vulnerability in Ghost Node.js content management system affected versions 5.121.0 through 5.130.5 and 6.0.0 through 6.10.3. The flaw in Staff Token authentication handling allowed unauthorized access to endpoints that should only be accessible via Staff Session authentication. External systems authenticated with Staff Tokens for Admin/Owner-role users could access restricted endpoints. The issue has been patched in versions 5.130.6 and 6.11.0.

Technical details

Mitigation steps:

Affected products:

Ghost CMS

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page