THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-7mpp-r37j-x5wh (medium) — Ghost: Session Fixation in Ghost Admin

[GHSA] GHSA-7mpp-r37j-x5wh (medium) — Ghost: Session Fixation in Ghost Admin

highgithub_advisoriesPublished 2026-08-04

GHSA-7mpp-r37j-x5wh Severity: medium CVE: CVE-2026-70594

Ghost: Session Fixation in Ghost Admin

### Impact

Ghost Admin did not invalidate existing sessions on login which could have allowed for session fixation attacks. Successful exploitation would have required another vulnerability on the same domain where Ghost Admin was hosted.

### Vulnerable versions

This vulnerability is present in Gho

Indicators of compromise

Original source: https://github.com/advisories/GHSA-7mpp-r37j-x5wh