{"id":"CVE-2026-103280","summary":"Ghost 0.8.0 before 6.23.0 Information Disclosure via Setup Endpoint","details":"Ghost from version 0.8.0 before 6.23.0 contains an information disclosure vulnerability in its setup endpoint: the endpoint responds to unauthenticated requests with the site owner's email address, allowing any remote visitor to obtain it.","aliases":["GHSA-5685-hwm9-62cg"],"modified":"2026-10-03T03:46:34.159176254Z","published":"2026-10-01T10:42:16.773Z","database_specific":{"cwe_ids":["CWE-201"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/103xxx/CVE-2026-103280.json","cna_assigner":"VulnCheck"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/103xxx/CVE-2026-103280.json"},{"type":"ADVISORY","url":"https://github.com/TryGhost/Ghost/security/advisories/GHSA-5685-hwm9-62cg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103280"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/ghost-0.8.0-before-6.23.0-information-disclosure-via-setup-endpoint"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/tryghost/ghost","events":[{"introduced":"8993778f8b71f7d5d47905aa1df8767c54868c50"},{"fixed":"e494949a92346da25e5bbed29e16ff586e99f857"}],"database_specific":{"extracted_events":[{"introduced":"0.8.0"},{"fixed":"6.23.0"}],"source":["AFFECTED_FIELD","DESCRIPTION"]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-103280.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}]}