Impact
Ghost CMS versions 3.20.2 through 6.50.x contain a server‑side request forgery flaw in the image‑size refetching logic. When a staff user supplies an image URL in a content block, Ghost unconditionally fetches that URL to determine its dimensions. An attacker who can log in as a staff user can inject arbitrary URLs, making Ghost initiate outbound HTTP requests to any destination reachable from the server. This grants the attacker the ability to probe internal network services, retrieve metadata, or exfiltrate data that would otherwise be inaccessible from the public Internet.
Affected Systems
The vulnerability affects the TryGhost Ghost CMS product, specifically all releases from 3.20.2 up to and including 6.50.x. No version prior to 3.20.2 or 6.51.0 and later is known to be impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. Because the attack requires a valid authenticated staff session, an attacker must first compromise credentials or acquire a staff account. The lack of a CISA KEV listing and an unavailable EPSS score suggest that widespread exploitation has not yet been reported, but the potential to reach internal services makes it a noteworthy risk for environments where Ghost is exposed externally.
OpenCVE Enrichment