
CVE@CVEnew
Disclosure
CVE-2026-70594 Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions on login which could have allowed for session … https://www.cve.org/CVERecord?id=CVE-2026-70594
Post summary
This entry announces a session‑invalidating flaw in Ghost CMS (CVE-2026-70594) that could enable session fixation between versions 2.2.0 and 6.54.1. No proof‑of‑concept, exploit, active exploitation, or patch information is provided.
000211.1K
58.1K followersView on X
