THREAT OPS › Threat News › [GHSA] GHSA-7mpp-r37j-x5wh (medium) — Ghost: Session Fixation in Ghost Admin
[GHSA] GHSA-7mpp-r37j-x5wh (medium) — Ghost: Session Fixation in Ghost Admin
GHSA-7mpp-r37j-x5wh Severity: medium CVE: CVE-2026-70594
Ghost: Session Fixation in Ghost Admin
### Impact
Ghost Admin did not invalidate existing sessions on login which could have allowed for session fixation attacks. Successful exploitation would have required another vulnerability on the same domain where Ghost Admin was hosted.
### Vulnerable versions
This vulnerability is present in Gho
Indicators of compromise
- CVE-2026-70594cve
- https://hub.docker.com/_/ghosturl
- https://docs.ghost.org/install/docker#updating-ghosturl
- https://docs.ghost.org/updateurl
- security@ghost.orgemail
Original source: https://github.com/advisories/GHSA-7mpp-r37j-x5wh