CVE-2026-105682

Summary

Ghost is a Node.js content management system. From 1.18.0 until 6.27.0, an SSRF vulnerability in the webhooks feature allowed staff users to probe internal hosts from the Ghost server. This issue is fixed in version 6.27.0.

Affected Software

VendorProductVersion RangeStatus
TryGhostGhost>= 1.18.0, < 6.27.0affected

Weaknesses

  • CWE-918: CWE-918: Server-Side Request Forgery (SSRF)

References