CVE-2026-29784 is a Cross-Site Request Forgery (CSRF) vulnerability affecting Ghost, a Node.js content management system, specifically versions 5.101.6 through 6.19.2. The flaw lies in incomplete CSRF protections around the /session/verify endpoint, allowing One-Time Codes (OTCs) to be used in login sessions different from the requesting session. This could facilitate phishing attacks and lead to Ghost site takeovers. The vulnerability is rated High severity with a CVSS score of 7.5, indicating a network-based attack with high impact on confidentiality, integrity, and availability, but requiring user interaction and high attack complexity. While the EPSS score is very low, suggesting a low probability of exploitation in the wild, the FAUCET Risk Score is 48/100. Currently, there is no known active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. However, the vulnerability has garnered some community discussion, with three mentions across platforms like Bluesky and Mastodon, highlighting its potential impact and the need for prompt patching. The issue has been patched in Ghost version 6.19.3.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.101.6, < 6.19.3CPE matchmatch criteria | cpe:2.3:a:ghost:ghost:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.