Junglewise Threat Intelligence

CVE-2026-59817: TryGhost Ghost authorization bypass in donation checkout flow

CVE-2026-59817 · Severity: medium · CVSS 5.3 · Published 2026-07-09

Technologies: ghost (npm). Vendors: npm.

Executive brief

A vulnerability in the Ghost publishing platform's donation feature allowed users to obtain full-priced paid gift memberships for a minimal, arbitrary cost. This issue impacts the revenue model of sites using the donation feature but did not expose sensitive customer data or allow for the theft of funds from the site or its members. Organizations using Ghost should update to the latest version or temporarily disable the 'Tips & donations' setting to mitigate this risk.

Technical details

A vulnerability exists in the public donation checkout flow of Ghost (versions 6.27.0 to 6.43.1) due to insufficient validation of web parameters during the transaction process. The flaw is classified under CWE-472 (External Control of Assumed-Immutable Web Parameter) and CWE-639 (Authorization Bypass Through User-Controlled Key), where an unauthenticated attacker could manipulate the checkout path to acquire paid gift memberships at a price lower than intended. The attack is reachable over the network without prior authentication or user interaction. The issue has been patched in version 6.44.0. As a workaround, administrators can disable the 'Tips & donations' feature in the Ghost Admin settings.

Affected products

  • Ghost Foundation Ghost >= 6.27.0, < 6.44.0

Timeline

  • 2026-06-23: disclosed: Initial disclosure by sane100400 and p4p3r
  • 2026-07-09: advisory: NVD publication date
  • 2026-08-04: patched: GitHub Advisory updated and reviewed

References

Related threats