THREAT OPS › Threat News › [GHSA] GHSA-chgm-3698-jm42 (medium) — Ghost: Member existence leak via magic link sign-in response
[GHSA] GHSA-chgm-3698-jm42 (medium) — Ghost: Member existence leak via magic link sign-in response
GHSA-chgm-3698-jm42 Severity: medium CVE: CVE-2026-53947
Ghost: Member existence leak via magic link sign-in response
### Impact
A discrepancy in responses from the members signin endpoints made it possible for an unauthenticated attacker to determine whether a given email address belongs to a registered member of a Ghost site.
### Vulnerable versions
This vulnerability is present in Ghost fr
Indicators of compromise
- CVE-2026-53947cve
- https://hub.docker.com/_/ghosturl
- https://docs.ghost.org/install/docker#updating-ghosturl
- https://docs.ghost.org/updateurl
- security@ghost.orgemail
Original source: https://github.com/advisories/GHSA-chgm-3698-jm42