CVE-2026-105678

medium

Description

Ghost is a Node.js content management system. From 0.5.0 until 6.64.0, staff users with the Editor or Super Editor role were able to assign their own role to Author and Contributor users, despite not having permission to assign that role. This issue is fixed in version 6.64.0.

References

https://github.com/TryGhost/Ghost/security/advisories/GHSA-4pvx-fwjj-8gpc

https://github.com/TryGhost/Ghost/releases/tag/v6.64.0

https://github.com/TryGhost/Ghost/issues/30764

https://github.com/TryGhost/Ghost/commit/99c5642b9bb481df4811a004a6f19d6143ed9aaf

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-92769

Details

Source: Mitre, NVD

Published: 2026-10-05

Updated: 2026-10-07

Risk Information

CVSS v2

Base Score: 4

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 4.3

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Severity: Medium

EPSS

EPSS: 0.00196