THREAT OPS › Threat News › [GHSA] GHSA-xm43-3m56-w3wf (medium) — Ghost: Paid gift memberships obtainable at minimal cost via the donations feature
[GHSA] GHSA-xm43-3m56-w3wf (medium) — Ghost: Paid gift memberships obtainable at minimal cost via the donations feature
GHSA-xm43-3m56-w3wf Severity: medium CVE: CVE-2026-59817
Ghost: Paid gift memberships obtainable at minimal cost via the donations feature
### Impact
A vulnerability in Ghost's public donation checkout flow allowed an unauthenticated attacker to obtain full paid gift memberships for a minimal payment. No customer or member data was exposed, and the issue could not be used to steal money from a
Indicators of compromise
- CVE-2026-59817cve
- https://hub.docker.com/_/ghosturl
- https://docs.ghost.org/install/docker#updating-ghosturl
- https://docs.ghost.org/updateurl
- https://hackerone.com/p4p3r_hakurl
- security@ghost.orgemail
Original source: https://github.com/advisories/GHSA-xm43-3m56-w3wf