MEDIUMnpm →
Ghost: Paid gift memberships obtainable at minimal cost via the donations feature
Ghost: Paid gift memberships obtainable at minimal cost via the donations feature
Affected packages
- ghost
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- 0.26%
- EPSS percentile
- 17.3%
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 17%.
Sources
- https://github.com/TryGhost/Ghost/security/advisories/GHSA-xm43-3m56-w3wf
- https://nvd.nist.gov/vuln/detail/CVE-2026-59817
- https://github.com/TryGhost/Ghost/pull/28351
- https://github.com/TryGhost/Ghost/pull/28352
- https://github.com/TryGhost/Ghost/commit/cab716cd015ac04b7ee50c7a405478d97bc7b1e0
- https://github.com/TryGhost/Ghost/commit/ee7b991b466a7849c70f9d1caed8e491ee4113c6
- https://github.com/TryGhost/Ghost
Structured record: https://osv.dev/vulnerability/GHSA-xm43-3m56-w3wf
Recommended response stack
Snyk — Scan your dependencies in CI and fix this vulnerability.→Socket — Detect malicious and compromised packages before they ship.→
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta