CVE-2026-103281
MEDIUM
NVD
CVSS Score
5.4
Severity
MEDIUM
Published
Oct 01, 2026
Vendor
unknown
Description
Ghost (npm package 'ghost') versions from 3.23.0 up to, but not including, 6.23.0 expose API keys to users with low-privilege staff accounts. An authenticated low-privilege staff user can read API keys returned by the Admin API, which are intended to be available only to higher-privileged users.