Impact
Version 1.18.0 through 6.26.99 of Ghost contains a server‑side request forgery in the webhook handler. Staff‑level users can create webhook requests that the Ghost server forwards internally, giving the attacker the ability to reach and enumerate resources inside the Ghost deployment’s network. The flaw does not directly grant code execution; it leaks information about internal hosts but could aid persistence or lateral movement.
Affected Systems
Ghost content management system, versions 1.18.0 up to 6.26.99. The vulnerable feature is the webhook endpoint and users with staff permissions. Affected vendors: TryGhost under the Ghost product line.
Risk and Exploitability
The CVSS base score of 5.1 indicates a medium‑severity vulnerability, and the EPSS score is not available, meaning no public data on exploitation frequency. The flaw is not currently listed in CISA’s KEV catalog. Inferred attack path: a compromised or malicious staff user crafts a malicious webhook URL that points to an internal address. The Ghost server then initiates a request to that address and returns the response in the webhook payload. Because the exploit requires staff access, brute‑force or credential‑guessing would be needed, but an insider or a compromised staff account can exploit it instantly.
OpenCVE Enrichment