{"id":"GHSA-w52v-v783-gw97","summary":"Ghost has a SQL injection in Content API","details":"### Impact\n\nA SQL injection vulnerability existed in Ghost's Content API that allowed unauthenticated attackers to read arbitrary data from the database. \n\n### Vulnerable Versions\n\nThis vulnerability is present in Ghost v3.24.0 to v6.19.0.\n\n### Patches\n\nv6.19.1 contains a fix for this issue. \n\n**Note:** as this vulnerability lets an attacker gain access to a site's API keys, we recommend reviewing staff users and rotating keys. We generally recommend always updating Ghost to its most current version. \n\n### Workarounds\n\nThere is no application-level workaround. The Content API key is public by design, so restricting key access does not mitigate this vulnerability.\n\nAs a temporary mitigation, a reverse proxy or WAF rule can be used to block Content API requests containing `slug%3A%5B` or `slug:[` in the query string filter parameter. Note that this may break legitimate slug filter functionality.\n\n### References\n\nWe thank Nicholas Carlini using Claude, Anthropic for disclosing this vulnerability responsibly. \n\n### For more information\nIf you have any questions or comments about this advisory, email us at [security@ghost.org](mailto:security@ghost.org).","aliases":["BIT-ghost-2026-26980","CVE-2026-26980"],"modified":"2026-06-08T23:30:21.094303476Z","published":"2026-02-18T21:50:23Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-02-18T21:50:23Z","nvd_published_at":"2026-02-20T02:16:54Z","cwe_ids":["CWE-89"],"severity":"CRITICAL"},"references":[{"type":"WEB","url":"https://github.com/TryGhost/Ghost/security/advisories/GHSA-w52v-v783-gw97"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-26980"},{"type":"WEB","url":"https://github.com/TryGhost/Ghost/commit/30868d632b2252b638bc8a4c8ebf73964592ed91"},{"type":"WEB","url":"https://blog.xlab.qianxin.com/ghost-cms-page-poisoning-cve-2026-26980"},{"type":"PACKAGE","url":"https://github.com/TryGhost/Ghost"},{"type":"WEB","url":"https://github.com/TryGhost/Ghost/releases/tag/v6.19.1"}],"affected":[{"package":{"name":"ghost","ecosystem":"npm","purl":"pkg:npm/ghost"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.24.0"},{"fixed":"6.19.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-w52v-v783-gw97/GHSA-w52v-v783-gw97.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L"}]}