Résumé
Ghost: Session Fixation in Ghost Admin
Détails de l’avis
Impact
Ghost Admin did not invalidate existing sessions on login which could have allowed for session fixation attacks. Successful exploitation would have required another vulnerability on the same domain where Ghost Admin was hosted.
Vulnerable versions
This vulnerability is present in Ghost from v2.2.0 to v6.54.0.
Patches
v6.54.1 contains a fix for this issue.
How to update
For self-hosters using Docker, find Docker's official Ghost image here. Updating a Docker-based Ghost instance is documented here.
If your Ghost is a Ghost-CLI install see our documentation on updating it to the latest version here.
References
Ghost thanks meifukun for disclosing this vulnerability responsibly.
For more information
If you have any questions or comments about this advisory, email Ghost at security@ghost.org.
Références
- https://github.com/advisories/GHSA-7mpp-r37j-x5wh
- https://github.com/TryGhost/Ghost/security/advisories/GHSA-7mpp-r37j-x5wh
- https://github.com/TryGhost/Ghost/pull/29634
- https://github.com/TryGhost/Ghost/commit/6b1c85c30dd0bacb4d5ffe64fc675ac9342d800c
- https://github.com/TryGhost/Ghost/releases/tag/v6.54.1
Vulnérabilités liées
Tout Supply chain →- MEDIUMCVE-2026-69245
Guzzle: Noncanonical cookie domain keeps subdomain scope
- MEDIUMCVE-2026-59883
Guzzle: Cookie Disclosure and Injection via IP-Address Domains
- HIGHGHSA-7q9c-hpx7-9cwm
TypeSpec: Unauthenticated Remote Shutdown of Spector Mock Server via POST /.admin/stop
- CRITICALCVE-2026-73842
OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation
- MEDIUMCVE-2026-73557
vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts
- MEDIUMCVE-2026-73556
vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m