CVE-2026-103281: Ghost 3.23.0 before 6.23.0 API Key Exposure via Admin API
Ghost (npm package 'ghost') versions from 3.23.0 up to, but not including, 6.23.0 expose API keys to users with low-privilege staff accounts. An authenticated low-privilege staff user can read API keys returned by the Admin API, which are intended to be available only to higher-privileged users.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/ghostto a version that resolves this vulnerability.Fixed in 6.23.0
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs an authenticated low-privilege Ghost staff account. The issue does not describe unauthenticated access.
Which deployments are affected?
Ghost npm package versions from 3.23.0 up to, but excluding, 6.23.0 are affected. Version 6.23.0 and later are not identified as affected.
What can a successful attacker access?
A low-privilege staff user can read API keys returned by the Admin API, despite those keys being intended only for higher-privileged users.
How can I determine whether my instance is exposed?
Verify the installed Ghost version and review whether low-privilege staff accounts can access Admin API responses containing API keys. Instances running a version in the affected range with such staff accounts are exposed.