VYPR
Moderate severityNVD Advisory· Published Jul 9, 2026· Updated Jul 14, 2026

Ghost: Paid gift memberships obtainable at minimal cost via the donations feature

CVE-2026-59817

Description

Ghost is a Node.js content management system. From 6.27.0 before 6.44.0, Ghost's public donation checkout flow allowed an unauthenticated attacker to control donation checkout metadata and obtain full paid gift memberships for a minimal payment without exposing customer or member data or stealing money from a site or its members. This issue is fixed in version 6.44.0.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
ghostnpm
>= 6.27.0, < 6.44.06.44.0

Affected products

2

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.