Impact
Ghost 6.54.1 through 6.65.0 suffer a validation flaw that lets an unauthenticated user force the application to make HTTP requests to internal hosts via bookmark fetching. The attacker cannot obtain response data, so the immediate damage is restricted to triggering outbound connections, which might aid further internal attacks. This weakness is categorized as a form of Server‑Side Request Forgery, reflecting a failure to validate remote addresses or prevent unintended outbound traffic.
Affected Systems
The vulnerability affects Ghost content‑management systems from version 6.54.1 up through 6.65.0, inclusive. All installations of TryGhost:Ghost within that range are susceptible unless the affected feature is disabled or the software is updated.
Risk and Exploitability
The CVSS score of 4.0 indicates a moderate risk. The EPSS score is not available, so the current exploitation probability is unknown. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog (KEV). An attacker can exploit it by sending crafted requests to the Ghost instance from outside, with the ability to target internal network hosts. Because no data is returned, immediate impact is limited, but the exposure may be leveraged for reconnaissance or to facilitate additional attacks against internal resources.
OpenCVE Enrichment