Aug 5, 2026·5 min read·32 visits
Ghost Admin did not rotate session identifiers upon login. This allowed session fixation attacks, enabling attackers with subdomain or domain-level cookie injection capabilities to hijack administrative sessions.
A critical session fixation vulnerability exists in the Ghost Admin panel from version 2.2.0 until 6.54.1. The Express-based authentication backend fails to invalidate or rotate the session identifier during login, allowing attackers to hijack administrative sessions.
The Ghost content management system uses an Express-based backend to manage administrator authentication and session states. The administration interface, known as Ghost Admin, exposes API endpoints designed to authenticate users and issue session tokens. Historically, this authentication workflow accepted existing session cookies without validating whether they were established prior to authentication.
This behavior exposes the application to session fixation vulnerabilities categorized under CWE-384. By maintaining the same session identifier before and after a user logs in, the backend fails to separate unauthorized and authorized states. If an attacker can inject a chosen session ID into a victim's browser, the attacker can hijack the session once the victim authenticates.
The vulnerability originates in the administrative session establishment process managed by the createSessionForUser function in the authentication service. When an administrator authenticates via the /ghost/api/admin/session/ endpoint, the server processes the login request and updates the current session state stored in the backend database. However, the system does not generate a new cryptographic session key.
Instead, the server maps the authenticated user metadata onto the existing, pre-login session object associated with the incoming request. Because this pre-login session identifier remains completely unchanged, any party holding the original cookie gains immediate administrative privileges upon the user's successful authentication. Successful exploitation relies on a secondary mechanism to plant the pre-login cookie, such as cookie tossing from a co-hosted subdomain or exploiting local cross-site scripting.
In vulnerable versions of Ghost, the session setup routine directly retrieved and modified the existing session object. The following code demonstrates the lack of session regeneration:
// Vulnerable Implementation
async function createSessionForUser(req, res, user) {
const session = await getSession(req, res);
const origin = getOriginOfRequest(req);
await assignUserToSession({
session,
user,
origin
});
}The fix introduced in version 6.54.1 remediates this flaw by invoking the regenerate() function provided by express-session. This method destroys the previous session identifier and replaces it with a new, cryptographically secure token. The patch also copies necessary metadata, such as multi-factor authentication challenges, while isolating user contexts:
// Patched Implementation in v6.54.1
async function createSessionForUser(req, res, user) {
const previousSession = await getSession(req, res);
const {
user_id: previousUserId,
verified: previousVerified,
auth_code_challenge: previousAuthCodeChallenge,
auth_code_generated_at: previousAuthCodeGeneratedAt
} = previousSession;
await new Promise((resolve, reject) => {
req.session.regenerate((err) => {
if (err) {
reject(err);
return;
}
resolve();
});
});
const session = req.session;
session.user_id = previousUserId;
session.verified = previousUserId && previousUserId !== user.id ? undefined : previousVerified;
session.auth_code_challenge = previousAuthCodeChallenge;
session.auth_code_generated_at = previousAuthCodeGeneratedAt;
const origin = getOriginOfRequest(req);
await assignUserToSession({
session,
user,
origin
});
}Exploitation of CVE-2026-70594 requires the attacker to plant a known session cookie into the target user's browser. Since Ghost Admin restricts cookie paths, the attacker must bypass domain isolation boundaries to perform a cookie injection or cookie tossing attack. This requires hosting a malicious application on a sibling subdomain or exploiting a secondary vulnerability on the same parent domain.
Once the victim's browser is loaded with the fixated cookie, the victim visits the Ghost Admin panel and enters their credentials. The Ghost server updates the backend storage associated with the fixated cookie. The attacker, who already possesses this cookie value, can then access administrative endpoints directly without prompting for credentials.
Successful exploitation of this session fixation vulnerability grants the attacker full administrative access to the Ghost CMS backend. Administrative access allows the compromise of publishing rights, enabling attackers to inject malicious scripts, modify public articles, or deface the site. Furthermore, the attacker gains access to the database of registered users, API keys, and system configuration settings.
The CVSS v3.1 base score is 6.7, reflecting a Medium severity rating. The attack vector is restricted to adjacent networks or specific local-domain topologies due to cookie domain constraints. High confidentiality, integrity, and availability impacts are limited only by the privileges associated with the targeted administrator account.
To remediate the vulnerability, deployers must update their installations to Ghost version 6.54.1 or later. This version incorporates the req.session.regenerate() logic to ensure immediate invalidation of the pre-login session. To apply the patch, run ghost update within the server command-line interface.
In environments where patching cannot be completed immediately, apply defense-in-depth domain isolation. Do not co-host untrusted applications on sibling subdomains of the same parent domain. Configure reverse proxies to set the HostOnly attribute on administrative cookies and enforce strict SameSite=Lax or SameSite=Strict directives to limit unauthorized session manipulation.
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L| Product | Affected Versions | Fixed Version |
|---|---|---|
Ghost TryGhost | >= 2.2.0, < 6.54.1 | 6.54.1 |
| Attribute | Detail |
|---|---|
| CWE ID | CWE-384 |
| Attack Vector | Adjacent Network |
| Attack Complexity | High |
| CVSS Score | 6.7 (Medium) |
| Exploit Status | Proof-of-Concept |
| CISA KEV Status | Not Listed |
The application authenticates a user without first invalidating the existing session identifier, thereby keeping the same session identifier after authentication.
A technical analysis of CVE-2026-107397, a stored Cross-Site Scripting (XSS) vulnerability in Indico's collaborative notes editor and custom link generation fields. Prior to version 3.3.13, Marshmallow serialization schemas omitted HTML sanitization during conflict resolution, and form validators failed to enforce strict URI schemes, enabling authenticated low-privilege attackers to execute arbitrary JavaScript.
An authorization bypass vulnerability exists in the legacy session export API of Indico, an open-source event management system developed at CERN. Due to a missing object-level access check, authenticated users can bypass configuration-level restrictions to extract private session metadata (including session titles, descriptions, and list of conveners) from events that they are otherwise authorized to view.
An incomplete Server-Side Request Forgery (SSRF) validation check in Indico prior to version 3.3.13 allows authenticated event organizers to bypass outbound network restrictions. By utilizing backslash characters within crafted URLs, attackers can exploit a parser differential between the application's validator and the downstream HTTP client library to access internal network resources.
CVE-2026-107717 represents a critical prompt boundary bypass and chat role injection vulnerability in the Banks Python package (versions prior to 2.5.0). The library parses generated template outputs line-by-line, attempting to validate each segment as a JSON-serialized ChatMessage object without validating the source boundaries of the text. If an application integrates user input directly into a prompt template, a remote, unauthenticated attacker can supply multi-line inputs with structured JSON payloads. This input is then parsed as high-privilege system instructions or tool execution responses, completely hijacking downstream Large Language Model behavior.
Improper pathname limitation and link resolution (CWE-22 and CWE-59) in the banks library prior to version 2.5.1 allow local attackers to read or write arbitrary files via crafted symbolic links in the prompt directory registry.
Improper validation of dynamic class resolution within Hazelcast's Zero Config Compact Serialization allows unauthenticated clients to trigger reflective class instantiation. This flaw can be exploited to read arbitrary JVM heap or off-heap memory, crash cluster nodes, or achieve arbitrary code execution under specific classpath conditions. This issue is resolved in Hazelcast versions 5.4.5, 5.5.10, 5.6.1, and 5.7.0.