Executive brief
Ghost is a popular content management system used to publish and manage websites and blogs. This vulnerability in the one-time code (OTC) login feature allows attackers to bypass cross-site request forgery protections, potentially enabling phishing attacks that could lead to unauthorized access to Ghost administration interfaces. Attackers could use this to take over a Ghost site with relatively low technical complexity but requiring user interaction.
Technical details
This vulnerability is a cross-site request forgery (CSRF) protection bypass in Ghost's /session/verify endpoint that handles one-time code (OTC) verification during login. The incomplete CSRF protections allow an attacker to use OTCs in login sessions different from the requesting session, effectively decoupling the token from the session context it was intended for. The attack requires user interaction (a user must click a phishing link) and network access, but no authentication or special privileges. An attacker can exploit this via phishing to redirect a user's OTC authentication to an attacker-controlled session, gaining administrative access to the Ghost site. The fix is available in version 6.19.3.
Affected products
- Ghost Ghost 5.101.6 to 6.19.2
Timeline
- 2026-03-05: disclosed: Vulnerability disclosed via GHSA-9m84-wc28-w895
- 2026-03-05: patched: Fix released in Ghost v6.19.3