Description
Ghost versions 1.18.0 before 6.27.0 contain a server-side request forgery vulnerability in the webhooks feature that allows staff users to probe internal hosts. Attackers with staff privileges can craft webhook requests to access internal network resources from the Ghost server.
Published: 2026-10-01
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: Server‑Side Request Forgery enabling internal host probing
Action: Apply Patch
AI Analysis

Impact

Version 1.18.0 through 6.26.99 of Ghost contains a server‑side request forgery in the webhook handler. Staff‑level users can create webhook requests that the Ghost server forwards internally, giving the attacker the ability to reach and enumerate resources inside the Ghost deployment’s network. The flaw does not directly grant code execution; it leaks information about internal hosts but could aid persistence or lateral movement.

Affected Systems

Ghost content management system, versions 1.18.0 up to 6.26.99. The vulnerable feature is the webhook endpoint and users with staff permissions. Affected vendors: TryGhost under the Ghost product line.

Risk and Exploitability

The CVSS base score of 5.1 indicates a medium‑severity vulnerability, and the EPSS score is not available, meaning no public data on exploitation frequency. The flaw is not currently listed in CISA’s KEV catalog. Inferred attack path: a compromised or malicious staff user crafts a malicious webhook URL that points to an internal address. The Ghost server then initiates a request to that address and returns the response in the webhook payload. Because the exploit requires staff access, brute‑force or credential‑guessing would be needed, but an insider or a compromised staff account can exploit it instantly.

Generated by OpenCVE AI on October 1, 2026 at 14:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Ghost to version 6.27.0 or later, which patches the webhook SSRF flaw.
  • Restrict staff users’ ability to create or configure webhooks, or remove staff role from webhook configuration.
  • Disable the webhooks feature entirely in Ghost if it is not required, or isolate Ghost from sensitive internal networks through network segmentation to limit the scope.
  • Monitor Ghost logs for abnormal outbound requests and review webhook activity for signs of misuse.

Generated by OpenCVE AI on October 1, 2026 at 14:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description Ghost versions 1.18.0 before 6.27.0 contain a server-side request forgery vulnerability in the webhooks feature that allows staff users to probe internal hosts. Attackers with staff privileges can craft webhook requests to access internal network resources from the Ghost server.
Title Ghost 1.18.0 before 6.27.0 Server-Side Request Forgery via Webhook
First Time appeared Ghost
Ghost ghost
Weaknesses CWE-918
CPEs cpe:2.3:a:ghost:ghost:*:*:*:*:*:*:*:*
Vendors & Products Ghost
Ghost ghost
References
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T10:42:21.818Z

Reserved: 2026-09-30T10:59:26.443Z

Link: CVE-2026-103287

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-01T11:17:25.040

Modified: 2026-10-01T15:06:17.330

Link: CVE-2026-103287

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T14:45:10Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)