Insertion of Sensitive Information Into Sent Data in Ghost - #VU142543
Published: August 14, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to insertion of sensitive information into sent data in the setup endpoint when handling requests. A remote attacker can query the endpoint to disclose sensitive information.
The disclosed information is the site owner\'s email address.