Cross-site request forgery in Ghost - CVE-2026-29784
Published: April 27, 2026
Ghost
Detailed vulnerability description
The vulnerability allows a remote attacker to take over a Ghost site.
The vulnerability exists due to improper request binding in /session/verify when handling one-time code verification requests. A remote attacker can cause a one-time code to be used in a login session different from the requesting session to take over a Ghost site.
User interaction is required, and exploitation is only possible in some scenarios involving phishing.