Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-29784

30
FAUCET Score

CVE-2026-29784 is a Cross-Site Request Forgery (CSRF) vulnerability affecting Ghost, a Node.js content management system, specifically versions 5.101.6 through 6.19.2. The flaw lies in incomplete CSRF protections around the /session/verify endpoint, allowing One-Time Codes (OTCs) to be used in login sessions different from the requesting session. This could facilitate phishing attacks and lead to Ghost site takeovers. The vulnerability is rated High severity with a CVSS score of 7.5, indicating a network-based attack with high impact on confidentiality, integrity, and availability, but requiring user interaction and high attack complexity. While the EPSS score is very low, suggesting a low probability of exploitation in the wild, the FAUCET Risk Score is 48/100. Currently, there is no known active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. However, the vulnerability has garnered some community discussion, with three mentions across platforms like Bluesky and Mastodon, highlighting its potential impact and the need for prompt patching. The issue has been patched in Ghost version 6.19.3.

Impacted Technologies

VendorProductVersion(s)CPE
>= 5.101.6, < 6.19.3CPE matchmatch criteria
cpe:2.3:a:ghost:ghost:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.6
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.16%
Probability of exploitation in next 30 days
EPSS Percentile
5.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0016 is in the 4th percentile among its peer group of 14,848 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

npmpatch availablevia ghsa
Product: ghostFixed in: 6.19.3

Vendor Advisories (1)

npmGHSA-9m84-wc28-w895high

Ghost has incomplete CSRF protections around OTC use

Mar 5, 2026

References

github.com / TryGhost/Ghost/commit/ec065a774fa125953d2aa644a59cd8990329e0a0
Patch
github.com / TryGhost/Ghost/security/advisories/GHSA-9m84-wc28-w895
Vendor Advisory