CVE-2026-53947: Ghost: Member existence leak via magic link sign-in response
A discrepancy in responses from the members signin endpoints made it possible for an unauthenticated attacker to determine whether a given email address belongs to a registered member of a Ghost site.
References
- github.com/TryGhost/Ghost/commit/fb2bb634653d99de68fc42d415721d755284fe30
- github.com/TryGhost/Ghost/pull/26752
- github.com/TryGhost/Ghost/releases/tag/v6.21.1
- github.com/TryGhost/Ghost/security/advisories/GHSA-chgm-3698-jm42
- github.com/advisories/GHSA-chgm-3698-jm42
- nvd.nist.gov/vuln/detail/CVE-2026-53947
Code Behaviors & Features
Detect and mitigate CVE-2026-53947 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →