Observable discrepancy in Ghost - CVE-2026-53947
Published: July 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the members signin endpoints when handling magic link sign-in requests. A remote attacker can submit an email address to determine whether it belongs to a registered member to disclose sensitive information.