CVE-2026-53949
published 2026-06-24CVE-2026-53949: Ghost is a Node.js content management system. From 5.46.1 until 6.21.2, the validation applied to filters on the public API endpoints could be partially…
PriorityP432medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.36%
27.3th percentile
Ghost is a Node.js content management system. From 5.46.1 until 6.21.2, the validation applied to filters on the public API endpoints could be partially bypassed, making it possible to reveal private fields via a brute force attack. If SQLite was used as the database password hashes were fully accessible. If MySQL was used as the database the password hashes' case (uppercase / lowercase) would have been lost, which would likely have rendered a further brute force attack on the discovered hashes fruitless. This vulnerability is fixed in 6.21.2.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ghost | ghost | >= 5.46.1 < 6.21.2 | 6.21.2 |
| tryghost | ghost | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Ghost Content API filter bypass reveals private fields
ghsa·2026-08-05
CVE-2026-53949 [MEDIUM] CWE-200 Ghost Content API filter bypass reveals private fields
Ghost Content API filter bypass reveals private fields
### Impact
The validation applied to filters on the public API endpoints could be partially bypassed, making it possible to reveal private fields via a brute force attack. If SQLite was used as the database password hashes were fully accessible. If MySQL was used as the database the password hashes' case (uppercase / lowercase) would have been lost, which would likely have rendered a further brute force attack on the discovered hashes fruitless.
### Vulnerable versions
This vulnerability is present in Ghost from v5.46.1 up to v6.21.1.
### Patches
v6.21.2 contains a fix for this issue.
### How to update
For self-hosters using Docker, find [Docker's official Ghost image here](https://hub.docker.com/_/ghost). Updating a Docker-bas
VulDB
TryGhost up to 6.21.1 Public API information disclosure
vuldb·2026-06-24·CVSS 5.3
CVE-2026-53949 [MEDIUM] TryGhost up to 6.21.1 Public API information disclosure
A vulnerability marked as problematic has been reported in TryGhost Ghost up to 6.21.1. The affected element is an unknown function of the component Public API. This manipulation causes information disclosure.
The identification of this vulnerability is CVE-2026-53949. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-24
Published