Executive brief
Ghostfolio, an open-source wealth management platform, contains a security flaw in how it handles shared portfolio permissions. Users who have been granted "read-only" access to a portfolio can bypass these restrictions to modify tags on the owner's investment holdings. This can lead to the corruption of portfolio categorization, inaccurate financial reporting, and unauthorized data modification.
Technical details
A missing authorization check exists in the Ghostfolio 'PUT /api/v1/portfolio/holding/:dataSource/:symbol/tags' endpoint. The root cause is located in the 'updateHoldingTags' function within the portfolio controller, which fails to verify the 'Access.permissions' field when an 'Impersonation-Id' header is provided. While the 'ImpersonationService' correctly resolves the grantee's header to the grantor's ID, it does not validate if the grant is restricted to 'READ_RESTRICTED'. An attacker with a valid read-only share token can exploit this to assign or remove tags on a victim's holdings. This vulnerability is specific to this endpoint, as other write paths in the application correctly validate the authenticated user's ownership. A fix is available in the project's repository.
Affected products
- Ghostfolio Ghostfolio <= 3.6.0
Timeline
- 2026-06-01: other: Vulnerability reported to vendor via email.
- 2026-07-03: disclosed: Public issue opened on GitHub.
- 2026-07-07: advisory: CVE-2026-59709 published.
References
- https://github.com/ghostfolio/ghostfolio
- https://github.com/ghostfolio/ghostfolio/commit/697ef59e3b58bebc5c21a9e482e4f5643390f316
- https://github.com/ghostfolio/ghostfolio/issues/7196
- https://www.vulncheck.com/advisories/ghostfolio-unauthorized-portfolio-holding-tag-modification-via-missing-permission-check