CVE-2026-103285: Ghost 5.19.0 before 6.57.1 Cross-Site Request Forgery
Ghost versions from 5.19.0 before 6.57.1 contain a cross-site request forgery vulnerability in the post feedback functionality that allows attackers to submit feedback on behalf of logged-in users. Attackers can craft a malicious link to the feedback page that automatically submits feedback when visited by authenticated members without their knowledge or consent.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ghostto a version that resolves this vulnerability.Fixed in 6.57.1
Event History
Frequently Asked Questions
Which users are exposed to this issue?
Authenticated Ghost members who can access the post feedback page are exposed. The issue affects Ghost versions from 5.19.0 up to, but not including, 6.57.1.
What does an attacker need to exploit it?
An attacker needs to get an authenticated member to visit a crafted malicious link to the feedback page. No attacker authentication is required, but user interaction is required.
What can an attacker do through this vulnerability?
The attacker can cause feedback to be submitted on behalf of the logged-in member without that member's knowledge or consent. The provided information does not indicate impacts beyond unauthorized feedback submission.
What is the remediation?
Upgrade Ghost to version 6.57.1 or later. The provided data does not describe a workaround for installations that cannot be patched immediately.