CVE-2026-70594
MEDIUM6.7CVSS v3
—CVSS v2
0.16%
EPSS (exploit probability)
CWE-384CWE
Description
Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions on login which could have allowed for session fixation attacks. Successful exploitation would have required another vulnerability on the same domain where Ghost Admin was hosted. This issue is fixed in version 6.54.1.
CVSS v3 vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L
Affected routers (0)
No routers currently mapped to this CVE in our database.