
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-29784 is an incomplete CSRF protection vulnerability in Ghost, a Node.js content management system, affecting the /session/verify endpoint. The flaw allows one-time codes (OTCs) to be reused in login sessions different from the requesting session, potentially enabling phishing-based account takeover of Ghost sites. It affects Ghost versions 5.101.6 through 6.19.2 (inclusive) and was patched in version 6.19.3. The vulnerability was published on March 7, 2026, with the fix committed on March 9, 2026. The GitHub Security Advisory assigns a CVSS v3.1 score of 7.5 (High) with Attack Complexity: High, while Feedly's aggregated data reflects a score of 8.8 (High) (GitHub Advisory, Feedly).
The root cause is classified as CWE-352 (Cross-Site Request Forgery), specifically an incomplete implementation of CSRF protections around the /session/verify endpoint (GitHub Advisory). Prior to the fix, the TOTP-based OTC generation used only the user ID and admin session secret as inputs (secret + userId), without binding the token to the specific requesting session context. This meant a valid OTC obtained or intercepted in one session could be replayed in a different session. The patch modifies the otp.generate() and otp.verify() functions to include an optional session-specific context parameter, making OTCs cryptographically bound to the originating session and preventing cross-session reuse (GitHub Commit).
Successful exploitation could allow an attacker to take over a Ghost administrator account by reusing a valid OTC from a different session, bypassing the intended authentication flow. This grants unauthorized access to sensitive site content, configurations, user data, and administrative functions of the Ghost CMS instance. The impact spans confidentiality, integrity, and availability — an attacker with admin access could modify or delete content, exfiltrate data, or disrupt site operations (GitHub Advisory, Feedly).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure (Feedly). Exploitation requires user interaction (i.e., a phishing scenario where a victim is tricked into using an OTC obtained or manipulated by the attacker), and the GitHub Advisory rates attack complexity as High. The EPSS score is 0.000180 (approximately 0.018%), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
/session/verify endpoint within a different login session (the attacker's own session), exploiting the lack of session binding in OTC validation./session/verify from IP addresses or user agents inconsistent with the originating login session; multiple OTC verification attempts across different session IDs for the same user account./ghost/api/admin/session/verify) originating from unexpected referrers or origins.The primary remediation is to upgrade Ghost to version 6.19.3 or later, which contains the fix binding OTCs to their originating session (GitHub Advisory). For Docker-based deployments, update using the official Ghost Docker image; for Ghost-CLI installs, follow the standard update documentation. For those unable to patch immediately, mitigations include enforcing strong administrator passwords, monitoring for suspicious login activity, and conducting phishing awareness training to reduce the social engineering risk that this vulnerability depends upon (Feedly).
The advisory was published by Ghost maintainer lsinger on March 4, 2026, via the GitHub Security Advisory system (GitHub Advisory). Social media activity was limited, with mentions observed on Mastodon (thehackerwire and infosec.exchange accounts) shortly after disclosure. Red Hat also tracked the CVE in their security database, indicating broader ecosystem awareness (Feedly). Overall community reaction was measured, consistent with the moderate exploitation complexity and absence of a public PoC.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."