PT-2026-69158 · Unknown · Ghostfolio
CVE-2026-47127
·
Published
2026-08-07
·
Updated
2026-08-13
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Ghostfolio versions prior to 3.4.0
Description
The Stripe checkout success-URL handler at
GET /api/v1/subscription/stripe/callback?checkoutSessionId=<id> retrieves the Stripe Checkout Session by ID and grants a Premium subscription to the client reference id without verifying the session.payment status or session.status. Because this callback is the only path for creating Stripe-driven subscriptions and lacks stripe-signature verification, any authenticated user can obtain a 1-year Premium subscription without payment.Recommendations
Update to version 3.4.0.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ghostfolio