CVE-2026-103288: Ghost 5.9.0 before 6.44.1 Authorization Bypass via Comment Like
Ghost, an open-source publishing platform, contains an input validation flaw in its comment like feature in versions from 5.9.0 before 6.44.1. An authenticated member can delete comment likes or dislikes belonging to other users that they are not authorized to delete, resulting in an authorization bypass and unauthorized modification of comment engagement data.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ghostto a version that resolves this vulnerability.Fixed in 6.44.1
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated Ghost member can exploit it. The issue affects deployments where members can use the comment like feature.
What access does an attacker need?
The attacker needs a valid authenticated member account; no user interaction is required. They can delete likes or dislikes created by other users without authorization.
What is the impact of successful exploitation?
Successful exploitation permits unauthorized modification of comment engagement data by removing other users' comment likes or dislikes. The provided severity data indicates integrity impact only, with no stated confidentiality or availability impact.
Which versions are affected?
Ghost versions from 5.9.0 before 6.44.1 are affected. Updating to 6.44.1 or later addresses the affected version range.