Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-103281

MEDIUM NVD
CVSS Score 5.4
Severity MEDIUM
Published Oct 01, 2026
Vendor unknown

Description

Ghost (npm package 'ghost') versions from 3.23.0 up to, but not including, 6.23.0 expose API keys to users with low-privilege staff accounts. An authenticated low-privilege staff user can read API keys returned by the Admin API, which are intended to be available only to higher-privileged users.

References