THREAT OPS › Threat News › [GHSA] GHSA-4wx2-7gvj-qfq3 (medium) — Ghost: Archived Offers can be Redeemed
[GHSA] GHSA-4wx2-7gvj-qfq3 (medium) — Ghost: Archived Offers can be Redeemed
GHSA-4wx2-7gvj-qfq3 Severity: medium CVE: CVE-2026-70589
Ghost: Archived Offers can be Redeemed
### Impact
A missing validation check allowed users to redeem subscription offers that were no longer active.
### Vulnerable versions
This vulnerability is present in Ghost from v4.22.0 up to v6.54.0.
### Patches
v6.54.1 contains a fix for this issue.
### How to update
For self-hosters using Do
Indicators of compromise
- CVE-2026-70589cve
- https://hub.docker.com/_/ghosturl
- https://docs.ghost.org/install/docker#updating-ghosturl
- https://docs.ghost.org/updateurl
- security@ghost.orgemail
Original source: https://github.com/advisories/GHSA-4wx2-7gvj-qfq3