CVE-2026-70594: Ghost: Session Fixation in Ghost Admin
Ghost Admin did not invalidate existing sessions on login which could have allowed for session fixation attacks. Successful exploitation would have required another vulnerability on the same domain where Ghost Admin was hosted.
References
- github.com/TryGhost/Ghost/commit/6b1c85c30dd0bacb4d5ffe64fc675ac9342d800c
- github.com/TryGhost/Ghost/pull/29634
- github.com/TryGhost/Ghost/releases/tag/v6.54.1
- github.com/TryGhost/Ghost/security/advisories/GHSA-7mpp-r37j-x5wh
- github.com/advisories/GHSA-7mpp-r37j-x5wh
- nvd.nist.gov/vuln/detail/CVE-2026-70594
Code Behaviors & Features
Detect and mitigate CVE-2026-70594 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →