Server-Side Request Forgery in Ghost Webhooks by TryGhost
CVE-2026-103287
5.1MEDIUM
What is CVE-2026-103287?
Ghost versions 1.18.0 and earlier have a server-side request forgery issue within the webhooks feature. This vulnerability enables users with staff privileges to construct malicious webhook requests, gaining unauthorized access to internal network resources from the Ghost server. As a result, sensitive internal information could potentially be exposed to attackers leveraging this flaw.
Affected Version(s)
Ghost 1.18.0 < 6.27.0
References
CVSS V4
Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
0xkakash1
0xBassia
l3tchupkt
rooks00
Wernerina
