Back to list

Ghost has a SQL injection in Content API — CVE-2026-26980

GitHub · GitHub · CVE-2026-26980

ID
CVE-2026-26980
Date
Updated
Activity
Source
GitHub
Vendor
GitHub
Threat
critical
CVSS
9.4
EPSS
0.5431

Summary

### Impact A SQL injection vulnerability existed in Ghost's Content API that allowed unauthenticated attackers to read arbitrary data from the database. ### Vulnerable Versions This vulnerability is present in Ghost v3.24.0 to v6.19.0. ### Patches v6.19.1 contains a fix for this issue. **Note:** as this vulnerability lets an attacker gain access to a site's API keys, we recommend reviewing staff users and rotating…

Product

npm: ghost

What to do

General, cautious steps (verify details in the official source):

  • Prioritize patching or mitigation immediately (treat as actively risky).
  • Identify affected product versions in your inventory and verify whether you are impacted.
  • Apply vendor patches/updates or recommended mitigations as soon as available.
  • Read the official advisory for exact affected versions and remediation steps.

Official advisory

Related advisories