PatchSiren cyber security CVE debrief
CVE-2026-59817 TryGhost CVE debrief
CVE-2026-59817 is a vulnerability in Ghost's public donation checkout flow. An unauthenticated attacker could control donation checkout metadata and obtain full paid gift memberships for a minimal payment. This issue was fixed in version 6.44.0. Sites using Ghost versions before 6.44.0 should prioritize patching to prevent potential unauthorized access to paid gift memberships. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM.
- Vendor
- TryGhost
- Product
- Ghost
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-09
- Original CVE updated
- 2026-07-14
- Advisory published
- 2026-07-09
- Advisory updated
- 2026-07-14
Who should care
Sites using Ghost versions before 6.44.0 should prioritize patching to prevent potential unauthorized access to paid gift memberships. This includes site administrators, security teams, and developers responsible for maintaining Ghost installations.
Technical summary
The vulnerability in Ghost's public donation checkout flow allowed an unauthenticated attacker to control donation checkout metadata. This could be exploited to obtain full paid gift memberships for a minimal payment without exposing customer or member data or stealing money. The issue was addressed with the release of Ghost version 6.44.0. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM.
Defensive priority
Medium priority due to the potential for unauthorized access to paid memberships.
Recommended defensive actions
- Patch to Ghost version 6.44.0 or later
- Review and monitor donation checkout flows for suspicious activity
- Implement additional authentication and authorization checks
- Verify Ghost version and update if necessary
- Monitor for unusual activity in paid gift memberships
- Review compensating controls for exposed systems
- Track exceptions and retest remediated assets
Evidence notes
Evidence is based on official CVE and NVD records, as well as source references from GitHub. The CVE record was published on 2026-07-09T18:16:57.603Z and has not been modified since then. The vulnerability affects Ghost versions before 6.44.0. There are no known instances of exploitation. Official CVE and NVD records provide further details.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-59817 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-59817
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-59817 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-59817
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/TryGhost/Ghost/commit/cab716cd015ac04b7ee50c7a405478d97bc7b1e0
-
Source reference
Unverified legacy reference
URL: https://github.com/TryGhost/Ghost/commit/ee7b991b466a7849c70f9d1caed8e491ee4113c6
-
Source reference
Unverified legacy reference
URL: https://github.com/TryGhost/Ghost/pull/28351
-
Source reference
Unverified legacy reference
URL: https://github.com/TryGhost/Ghost/pull/28352
-
Source reference
Unverified legacy reference
URL: https://github.com/TryGhost/Ghost/security/advisories/GHSA-xm43-3m56-w3wf
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.