CVE-2026-103281

MEDIUM Status: Received

CVSS Scores

CVSS v3.x Base Score
5.4
MEDIUM

Description

Ghost (npm package 'ghost') versions from 3.23.0 up to, but not including, 6.23.0 expose API keys to users with low-privilege staff accounts. An authenticated low-privilege staff user can read API keys returned by the Admin API, which are intended to be available only to higher-privileged users.

Published
October 1, 2026 11:17 AM
Last Modified
October 1, 2026 11:17 AM
Source
[email protected]

Weaknesses (CWE)

CWE-201

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.