CVE-2026-105682
LOW
2,7
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: high
User Interaction: none
Scope: unchanged
Confidentiality: low
Integrity: none
Availability: none
Description
AI Translation Available
Ghost is a Node.js content management system. From 1.18.0 until 6.27.0, an SSRF vulnerability in the webhooks feature allowed staff users to probe internal hosts from the Ghost server. This issue is fixed in version 6.27.0.
918
Server-Side Request Forgery (SSRF)
IncompleteCommon Consequences
Security Scopes Affected:
Confidentiality
Integrity
Access Control
Potential Impacts:
Read Application Data
Execute Unauthorized Code Or Commands
Bypass Protection Mechanism
Applicable Platforms
Technologies:
Web Based, AI/ML, Web Server
https://github.com/TryGhost/Ghost/commit/815962dd2760e55c5dc8d0fb7fac732a763456…
https://github.com/TryGhost/Ghost/issues/27219
https://github.com/TryGhost/Ghost/releases/tag/v6.27.0
https://github.com/TryGhost/Ghost/security/advisories/GHSA-354h-gmhv-mr9c