Impact
A validation flaw in Ghost allows an unauthenticated user to trigger a Server‑Side Request Forgery (CWE‑918) through Webmentions. The attacker can cause the Ghost server to make HTTP requests to hosts within the server’s internal network, but the response payload is suppressed. The vulnerability does not expose user data directly, yet it enables the server to reach internal services that could be further abused.
Affected Systems
TryGhost Ghost versions from 6.26.0 up through 6.54.1 are affected. The issue is resolved starting with 6.54.1; earlier releases remain vulnerable.
Risk and Exploitability
The CVSS score of 4.0 indicates low severity. EPSS is not available and the CVE is not listed in CISA KEV. The likely attack vector is via unauthenticated Webmention requests, which can reach internal network hosts but provide no direct response data, limiting exploit impact. Nonetheless, the ability to reach internal services presents a potential foothold for further lateral movement.
OpenCVE Enrichment
Github GHSA