Insufficient Session Expiration in Ghost - #VU142542
Published: August 14, 2026
Vulnerability details
The vulnerability allows a remote user to maintain access to the affected account after a password change.
The vulnerability exists due to insufficient session expiration in Ghost admin when handling password reset and session invalidation. A remote user can use a previously stolen session cookie to maintain access to the affected account after a password change.