Description
Ghost is a Node.js content management system. From 6.54.1 until 6.65.0, a validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP requests to hosts in the Ghost server's internal network. A successful attack would not result in any response data being returned. This issue is fixed in version 6.65.0.
Published: 2026-10-05
Score: 4 Medium
EPSS: n/a
KEV: No
Impact: Server‑Side Request Forgery with limited internal network requests
Action: Apply Patch
AI Analysis

Impact

Ghost 6.54.1 through 6.65.0 suffer a validation flaw that lets an unauthenticated user force the application to make HTTP requests to internal hosts via bookmark fetching. The attacker cannot obtain response data, so the immediate damage is restricted to triggering outbound connections, which might aid further internal attacks. This weakness is categorized as a form of Server‑Side Request Forgery, reflecting a failure to validate remote addresses or prevent unintended outbound traffic.

Affected Systems

The vulnerability affects Ghost content‑management systems from version 6.54.1 up through 6.65.0, inclusive. All installations of TryGhost:Ghost within that range are susceptible unless the affected feature is disabled or the software is updated.

Risk and Exploitability

The CVSS score of 4.0 indicates a moderate risk. The EPSS score is not available, so the current exploitation probability is unknown. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog (KEV). An attacker can exploit it by sending crafted requests to the Ghost instance from outside, with the ability to target internal network hosts. Because no data is returned, immediate impact is limited, but the exposure may be leveraged for reconnaissance or to facilitate additional attacks against internal resources.

Generated by OpenCVE AI on October 5, 2026 at 20:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Ghost 6.65.0 or later, which addresses the validation issue.
  • If an upgrade is not feasible, disable the Webmentions feature or other bookmark‑fetching functionalities that can trigger outbound requests.
  • Configure network firewalls to restrict the Ghost instance’s outbound traffic to only trusted destinations.

Generated by OpenCVE AI on October 5, 2026 at 20:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Description Ghost is a Node.js content management system. From 6.54.1 until 6.65.0, a validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP requests to hosts in the Ghost server's internal network. A successful attack would not result in any response data being returned. This issue is fixed in version 6.65.0.
Title Ghost: Server-Side Request Forgery in Bookmark Fetching
Weaknesses CWE-367
CWE-918
References
Metrics cvssV3_1

{'score': 4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-05T19:52:13.593Z

Reserved: 2026-10-05T16:40:39.613Z

Link: CVE-2026-105647

cve-icon Vulnrichment

Updated: 2026-10-05T19:52:10.598Z

cve-icon NVD

Status : Received

Published: 2026-10-05T20:17:13.157

Modified: 2026-10-05T20:17:13.157

Link: CVE-2026-105647

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T21:00:21Z

Weaknesses
  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition

  • CWE-918

    Server-Side Request Forgery (SSRF)