PT-2026-69158 · Unknown · Ghostfolio

CVE-2026-47127

·

Published

2026-08-07

·

Updated

2026-08-13

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Ghostfolio versions prior to 3.4.0
Description The Stripe checkout success-URL handler at GET /api/v1/subscription/stripe/callback?checkoutSessionId=<id> retrieves the Stripe Checkout Session by ID and grants a Premium subscription to the client reference id without verifying the session.payment status or session.status. Because this callback is the only path for creating Stripe-driven subscriptions and lacks stripe-signature verification, any authenticated user can obtain a 1-year Premium subscription without payment.
Recommendations Update to version 3.4.0.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47127
GHSA-J465-X2W3-WJJ8

Affected Products

Ghostfolio