CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-59817

CVE-2026-59817: Premium Membership Provisioning Bypass via Parameter Tampering in Ghost CMS

Amit Schendel
Amit Schendel
Senior Security Researcher

Aug 4, 2026·6 min read·48 visits

Executive Summary (TL;DR)

Unauthenticated remote attackers can obtain premium paid subscriptions for nominal costs by exploiting weak metadata sanitization and logical errors in Ghost's Stripe checkout integration.

An unauthenticated remote business logic vulnerability in Ghost CMS versions 6.27.0 through 6.43.1 allows attackers to bypass paid subscription gates. By injecting reserved metadata fields into public donation Stripe Checkout Sessions, attackers can obtain premium-tier memberships for arbitrary nominal amounts.

Vulnerability Overview

Ghost is an open-source content management system built on Node.js that enables subscription-based monetization, membership routing, and donations using Stripe. The platform relies on Stripe's hosted Checkout Sessions to securely handle credit card processing. The checkout flow handles operations such as purchasing premium memberships, processing single donations, and issuing gift cards.

To map these detached operations back to internal states, the CMS registers critical transaction parameters directly into Stripe's checkout session metadata. This architectural design relies on Stripe Webhooks to asynchronously inform the server which specific entitlements must be granted once payment is confirmed. This framework introduces an attack surface when user-supplied input parameters are processed without validation prior to payment initialization.

The flaw indexed as CVE-2026-59817 represents a classic parameter tampering and business logic bypass vulnerability in the routing of donation payments. Due to improper metadata sanitization, unauthenticated remote actors can inject control keys into Stripe sessions. When Stripe confirms payment completion, the backend accepts the modified metadata as authentic, resulting in privilege escalation.

Root Cause Analysis

The root cause of CVE-2026-59817 is a multi-step input validation and logical routing failure in the Ghost backend components handling member checkouts. The flow begins when a user initiates a donation payment through the public REST endpoint mapped to the _createDonationCheckoutSession controller function.

First, the application failed to verify if the donations feature was actually toggled on by administrators. It verified only if the Stripe service was structurally configured, allowing users to reach the donation setup codepath even on deployments where donations were disabled. This oversight granted access to an unauthenticated, arbitrary-amount checkout path.

Second, the controller did not enforce metadata boundaries. During session creation, the incoming HTTP request payload allowed arbitrary keys to be placed inside the metadata object. Because the controller did not sanitize or blocklist reserved internal identifiers, these keys were forwarded to the Stripe API and appended to the valid Stripe Session.

Finally, when Stripe transmitted the asynchronous checkout.session.completed event, the webhook consumer parsed the returned metadata to determine how to process the transaction. Rather than validating that the subscription purchase price matched the financial total processed, the handler executed routing solely based on the presence of boolean flags inside the metadata. This allowed a low-value donation payment to be routed to gift-subscription code paths.

Technical Code Analysis

Analyzing the source code diff reveals how the validation gaps were closed. The primary flaw was localized within router-controller.js and mitigated by enforcing configuration checks and stripping control tags.

The vulnerability is mitigated by implementing a strict set of reserved keys and introducing a validation check to guarantee that donations are actively enabled. Below is the code implementation showing the introduced metadata blocklist:

// Patched: Define reserved metadata keys that control application state
const RESERVED_CHECKOUT_METADATA_KEYS = new Set([
    'ghost_donation',
    'ghost_gift',
    'ghostSignupContext',
    'gift_token',
    'tier_id',
    'cadence',
    'duration'
]);
 
// Patched: Explicit sanitization function to strip reserved attributes
function removeReservedCheckoutMetadata(metadata) {
    if (!metadata || typeof metadata !== 'object') {
        return;
    }
    for (const key of RESERVED_CHECKOUT_METADATA_KEYS) {
        delete metadata[key];
    }
}

The corresponding webhook receiver in checkout-session-event-service.js was also patched to enforce strict boolean evaluations on Stripe metadata fields and prevent conflicting states. It now logs a warning and rejects executions where conflicting flow markers are present:

// Patched: Enforce strict type check on webhook processing
function isStripeMetadataTrue(value) {
    return value === true || value === 'true';
}
 
function hasConflictingCheckoutFlowMetadata(metadata) {
    return hasStripeMetadataKey(metadata, 'ghost_donation') && hasStripeMetadataKey(metadata, 'ghost_gift');
}

Attack Methodology and Proof of Concept

To exploit this vulnerability, an attacker identifies a target site running a vulnerable version of Ghost CMS and locates the endpoint for creating checkout sessions. The attack requires no authentication or valid cookie credentials.

The attacker crafts a POST request to /api/create-stripe-checkout-session/ with the transaction type configured to donation. This allows the attacker to specify an arbitrary nominal value, such as $1.00. The attacker embeds reserved parameter fields within the unsanitized metadata nested object, simulating a valid paid gift subscription configuration.

{
  "customerEmail": "attacker@example.com",
  "type": "donation",
  "amount": 100,
  "successUrl": "https://example.com/success",
  "cancelUrl": "https://example.com/cancel",
  "metadata": {
    "ghost_gift": "true",
    "gift_token": "attacker_controlled_token_string",
    "tier_id": "prod_premium_tier_id",
    "cadence": "year",
    "duration": "12"
  }
}

The vulnerable server accepts this payload, generates a Stripe checkout session link containing the tampered metadata, and returns it to the attacker. The attacker completes the Stripe payment flow of $1.00. The Stripe event processor issues a webhook to Ghost, which identifies ghost_gift: "true" in the metadata, bypasses the payment tier check, and provisions a 12-month premium access token to the designated email.

Impact Assessment

The impact of CVE-2026-59817 is localized privilege escalation and monetary evasion, with a CVSS v3.1 score of 5.3 (Medium). The flaw does not present a mechanism for remote code execution, command injection, or administrative panel access, nor does it allow access to back-end system databases.

The operational impact is restricted to the bypass of premium content subscription fees. Threat actors can use the vulnerability to obtain active, long-term premium memberships without paying the defined registration fees, leading to revenue loss for creators and publishing entities using the platform.

Because the vulnerability is confined to CMS billing logic, no customer records, payment details, or personal identifying information are leaked or modified. It does not affect system-level availability or service reliability.

Remediation and Mitigation

The definitive remediation is to upgrade Ghost CMS to version 6.44.0 or newer. This update implements input scrubbing for public-facing Stripe endpoints and hardens the asynchronous validation of metadata properties within the Stripe webhook controllers.

If upgrading is not immediately possible, administrators should disable the Tips and Donations feature globally in the Ghost management console. This limits the ability of external actors to trigger custom-amount payment processes.

Administrators may also apply Web Application Firewall rules at the CDN or proxy layer (such as Cloudflare or Nginx) to inspect and block POST requests to /api/create-stripe-checkout-session/ if the payload contains any keys in the metadata object matching ghost_gift, gift_token, or tier_id.

Official Patches

TryGhostRemediation Commit for Metadata Whitelisting
TryGhostRemediation Commit for Settings Validation

Fix Analysis (2)

Technical Appendix

CVSS Score
5.3/ 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS Probability
0.26%
Top 83% most exploited

Affected Systems

Ghost CMS

Affected Versions Detail

Product
Affected Versions
Fixed Version
Ghost
TryGhost
>= 6.27.0, < 6.44.06.44.0
AttributeDetail
CWE IDCWE-915
Attack VectorNetwork (AV:N)
CVSS Score5.3 (Medium)
EPSS Score0.00257 (17.25 percentile)
ImpactIntegrity Level Low (I:L), No Confidentiality/Availability Impact
Exploit StatusProof-of-concept validated
KEV StatusNot Listed in CISA KEV

MITRE ATT&CK Mapping

T1190Exploit Public-Facing Application
Initial Access
T1548Abuse Elevation Control Mechanism
Privilege Escalation
CWE-915
Improperly Controlled Modification of Dynamically-Determined Object Attributes

The application allows user-controlled input to modify object attributes or metadata that should only be controlled by the server, leading to business logic bypass.

Vulnerability Timeline

Ghost release candidate version 6.43.2-rc.0 tagged to begin testing remediation logic
2026-05-29
Remediation commits ee7b991 and cab716c pushed addressing setting validation and sanitization
2026-06-03
Official GitHub Security Advisory GHSA-xm43-3m56-w3wf published
2026-07-09
National Vulnerability Database publishes CVE-2026-59817
2026-07-09

References & Sources

  • [1]GitHub Security Advisory GHSA-xm43-3m56-w3wf
  • [2]GitHub Pull Request #28351
  • [3]GitHub Pull Request #28352

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•about 1 hour ago•CVE-2026-107397
4.4

CVE-2026-107397: Stored Cross-Site Scripting via Collaborative Editor Conflict Resolution and Custom Link Fields in Indico

A technical analysis of CVE-2026-107397, a stored Cross-Site Scripting (XSS) vulnerability in Indico's collaborative notes editor and custom link generation fields. Prior to version 3.3.13, Marshmallow serialization schemas omitted HTML sanitization during conflict resolution, and form validators failed to enforce strict URI schemes, enabling authenticated low-privilege attackers to execute arbitrary JavaScript.

Alon Barad
Alon Barad
0 views•7 min read
•about 2 hours ago•CVE-2026-107395
4.3

CVE-2026-107395: Missing Authorization in Indico Legacy Session Export API

An authorization bypass vulnerability exists in the legacy session export API of Indico, an open-source event management system developed at CERN. Due to a missing object-level access check, authenticated users can bypass configuration-level restrictions to extract private session metadata (including session titles, descriptions, and list of conveners) from events that they are otherwise authorized to view.

Alon Barad
Alon Barad
5 views•5 min read
•about 3 hours ago•CVE-2026-107394
6.8

CVE-2026-107394: Server-Side Request Forgery Bypass via Parser Differential in Indico

An incomplete Server-Side Request Forgery (SSRF) validation check in Indico prior to version 3.3.13 allows authenticated event organizers to bypass outbound network restrictions. By utilizing backslash characters within crafted URLs, attackers can exploit a parser differential between the application's validator and the downstream HTTP client library to access internal network resources.

Alon Barad
Alon Barad
5 views•6 min read
•about 4 hours ago•CVE-2026-107717
6.5

CVE-2026-107717: Chat Role Injection and Prompt Boundary Bypass in Banks Library

CVE-2026-107717 represents a critical prompt boundary bypass and chat role injection vulnerability in the Banks Python package (versions prior to 2.5.0). The library parses generated template outputs line-by-line, attempting to validate each segment as a JSON-serialized ChatMessage object without validating the source boundaries of the text. If an application integrates user input directly into a prompt template, a remote, unauthenticated attacker can supply multi-line inputs with structured JSON payloads. This input is then parsed as high-privilege system instructions or tool execution responses, completely hijacking downstream Large Language Model behavior.

Alon Barad
Alon Barad
8 views•6 min read
•about 5 hours ago•CVE-2026-107716
7.3

CVE-2026-107716: Path Traversal and Link Following in banks DirectoryPromptRegistry

Improper pathname limitation and link resolution (CWE-22 and CWE-59) in the banks library prior to version 2.5.1 allow local attackers to read or write arbitrary files via crafted symbolic links in the prompt directory registry.

Amit Schendel
Amit Schendel
8 views•7 min read
•about 6 hours ago•CVE-2026-107726
9.3

CVE-2026-107726: Unrestricted Deserialization in Hazelcast Zero Config Compact Serialization

Improper validation of dynamic class resolution within Hazelcast's Zero Config Compact Serialization allows unauthenticated clients to trigger reflective class instantiation. This flaw can be exploited to read arbitrary JVM heap or off-heap memory, crash cluster nodes, or achieve arbitrary code execution under specific classpath conditions. This issue is resolved in Hazelcast versions 5.4.5, 5.5.10, 5.6.1, and 5.7.0.

Alon Barad
Alon Barad
6 views•6 min read