Improper authentication on some endpoints used for member actions would allow an attacker to perform member-only actions, and read member information.
This security vulnerability is present in Ghost v4.46.0-v5.89.5.
Ghost(Pro) customers are automatically updated to fixed versions ahead of disclosure.
If you're a self-hoster, please follow our update instructions.
v5.89.5 contains a fix for this issue.
Disable site membership in Ghost settings.
If you have any questions or comments about this advisory:
| Score | Percentile |
|---|---|
| 0.45% | 63.52% |
| Base score | Version | Severity | Vector |
|---|---|---|---|
| 6.5 | 3.1 | — |
|
| 6.9 | 4.0 | — |
|
| Type | Value |
|---|---|
| GHSA | GHSA-78x2-cwp9-5j42 ↗ |
| CVE | CVE-2024-43409 ↗ |
Vulnerable version ranges and first patched releases as published by GitHub.
| Ecosystem | Package | Vulnerable range | First patched | Vulnerable functions |
|---|---|---|---|---|
| npm | ghost | >= 4.46.0, < 5.89.5 | 5.89.5 | — |
| npm | @tryghost/portal | >= 1.22.2, < 2.39.0 | 2.39.0 | — |