CVE-2026-59817 Details
Description
Ghost is a Node.js content management system. From 6.27.0 before 6.44.0, Ghost's public donation checkout flow allowed an unauthenticated attacker to control donation checkout metadata and obtain full paid gift memberships for a minimal payment without exposing customer or member data or stealing money from a site or its members. This issue is fixed in version 6.44.0.
A vulnerability in Ghost, a Node.js content management system, was identified in versions 6.27.0 prior to 6.44.0. The issue allowed unauthenticated attackers to manipulate donation checkout metadata during the public donation process. Exploiting this vulnerability enabled attackers to obtain full paid gift memberships for a minimal payment, without exposing any customer or member data or stealing money from the site or its members. The vulnerability arose from the checkout flow not properly validating metadata, allowing for unauthorized membership gains.
Users can update to Ghost version 6.44.0, which addresses this vulnerability. For those using Docker, instructions for updating a Docker-based Ghost instance are available in the Ghost documentation. Self-hosters using Ghost-CLI can also find update instructions in the official Ghost documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 9, 2026CISA-ADP
Assessed Jul 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/TryGhost/Ghost/commit/cab716cd015ac04b7ee50c7a405478d97bc7b1e0 | [email protected] | Source CodeVendor |
| https://github.com/TryGhost/Ghost/commit/ee7b991b466a7849c70f9d1caed8e491ee4113c6 | [email protected] | Source CodeVendor |
| https://github.com/TryGhost/Ghost/pull/28351 | [email protected] | Issue TrackingVendor |
| https://github.com/TryGhost/Ghost/pull/28352 | [email protected] | Issue TrackingVendor |
| https://github.com/TryGhost/Ghost/security/advisories/GHSA-xm43-3m56-w3wf | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-472 | External Control of Assumed-Immutable Web Parameter | [email protected] |
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Ghost | >= 6.27.0, <= 6.43.1 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | CVE Modified | CISA-ADP |
| Jul 9, 2026 | New CVE Received | [email protected] |
Volerion