Executive brief
Ghost is a popular open-source publishing and membership platform. The member email change API contains an authentication bypass that allows attackers to take over member accounts by changing their email address to one controlled by the attacker. This enables account hijacking and potential unauthorized access to premium content or subscriber data.
Technical details
The vulnerability is an authentication bypass in Ghost's member email change functionality. An unauthenticated attacker can craft requests to the email change API endpoint to modify the email address of any member account, then validate the new email via a magic link sent to their address. The flaw affects Ghost versions 3.18.0 through 4.15.0 when members functionality is enabled. Attack requires only network access and no user interaction. The vulnerability was patched in versions 4.15.1 and 3.42.6, which add authentication checks to the email update endpoint. As a temporary workaround, the vulnerable POST /members/api/send-magic-link/ endpoint can be blocked.
Affected products
- TryGhost Ghost 3.18.0 through 4.15.0
Timeline
- 2021-09-23: disclosed
- 2021-09-23: patched: Fixed in Ghost 4.15.1 and 3.42.6