
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22596 is a SQL injection vulnerability in Ghost's Members Activity Feed, specifically in the /ghost/api/admin/members/events endpoint. It affects Ghost (Node.js CMS) versions 5.90.0 through 5.130.5 and 6.0.0 through 6.10.3. The vulnerability was discovered by Sho Odagiri of GMO Cybersecurity by Ierae, Inc. and disclosed on January 8, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 6.7 (Moderate) per the GitHub Security Advisory, though Feedly's data notes a score of 7.2 (High) from NVD (GitHub Advisory, Ghost Advisory).
The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), classified as a classic SQL injection flaw. In the vulnerable code within EventRepository.js, the getAggregatedClickEvents method extracted a postId value from the API filter parameter and interpolated it directly into a raw SQL query string (WHERE r.post_id = '${postId}') without validation or sanitization. An attacker with Admin API credentials could supply a crafted data.post_id filter value containing SQL metacharacters to break out of the intended query and execute arbitrary SQL against the database. The fix validates the postId as a proper BSON ObjectID using ObjectID.isValid() before use, rejecting any non-conforming input (Ghost Advisory, Patch Commit).
Successful exploitation allows an authenticated Admin API user to read sensitive data from the Ghost database (e.g., member records, subscription data, credentials), modify or delete database records, and potentially escalate privileges within the application. The vulnerability has high confidentiality and integrity impact, with low availability impact. While exploitation requires Admin API credentials, a compromised or malicious administrator could leverage this to exfiltrate the full database contents or tamper with member and subscription data (GitHub Advisory, Ghost Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure (GitHub Advisory). Exploitation requires valid Admin API authentication credentials, which significantly limits the attack surface. The EPSS score is approximately 0.051% (16th percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
/ghost/api/admin/members/events with a filter parameter containing a crafted data.post_id value that includes SQL injection payload (e.g., data.post_id:'; SELECT * FROM users; --).postId value is interpolated directly into the raw SQL query WHERE r.post_id = '${postId}', allowing the injected SQL to execute as part of the database query./ghost/api/admin/members/events with abnormal or encoded filter query parameters containing SQL metacharacters (e.g., single quotes, --, UNION, SELECT, DROP)./members/events endpoint with filter values that do not conform to valid ObjectID format (24-character hex strings); database error messages related to SQL syntax errors in application logs.users, members, subscriptions).Ghost has released patched versions 5.130.6 (for the 5.x branch) and 6.11.0 (for the 6.x branch) that resolve this vulnerability by validating the postId parameter as a BSON ObjectID before use in SQL queries. Administrators should upgrade immediately to one of these versions. As an interim measure, restrict Admin API access to trusted administrators only and apply the principle of least privilege for API credentials. Monitor Admin API activity logs for suspicious requests to the /ghost/api/admin/members/events endpoint (Ghost Advisory, Patch Commit).
The vulnerability was responsibly disclosed by Sho Odagiri of GMO Cybersecurity by Ierae, Inc., and Ghost acknowledged the researcher in both the security advisory and patch commit messages. The advisory was published simultaneously with the patch on January 8, 2026, following coordinated disclosure best practices. Community coverage was limited to automated vulnerability tracking platforms and aggregators; no significant independent researcher commentary or media coverage was identified (Ghost Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."