PatchSiren

ghostfolio CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM ghostfolio CVE published 2026-08-07

CVE-2026-47127

CVE-2026-47127 is a vulnerability in Ghostfolio, an open-source wealth management software. The issue allows an authenticated user to self-grant a 1-year Premium subscription without payment by exploiting the Stripe checkout success-URL handler. This was fixed in version 3.4.0, which adds payment status and session status checks. The vulnerability impacts Ghostfolio installations using Stripe checkout, al [truncated]

HIGH ghostfolio CVE published 2026-07-07

CVE-2026-59708

CVE-2026-59708 debrief based on the supplied source corpus. The vulnerability affects the Ghostfolio product, specifically the GET /api/v1/public/:accessId/portfolio endpoint, which accepts private access IDs without validating granteeUserId filtering. This allows unauthenticated access to full portfolio data, including holdings, quantities, buy prices, and performance metrics. Defenders should assess exp [truncated]

MEDIUM Ghostfolio CVE published 2026-07-07

CVE-2026-59709

CVE-2026-59709 debrief: Ghostfolio's PUT /api/v1/portfolio/holding/:dataSource/:symbol/tags endpoint fails to verify Access.permissions field when processing the Impersonation-Id header, allowing read-only access grantees to modify portfolio holding tags. This vulnerability affects Ghostfolio deployments with multiple users or integrations, potentially corrupting portfolio categorization and reports. Defe [truncated]