Server-Side Request Forgery in Ghost Webhooks by TryGhost
CVE-2026-103287

5.1MEDIUM

Key Information:

Vendor

Tryghost

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-103287?

Ghost versions 1.18.0 and earlier have a server-side request forgery issue within the webhooks feature. This vulnerability enables users with staff privileges to construct malicious webhook requests, gaining unauthorized access to internal network resources from the Ghost server. As a result, sensitive internal information could potentially be exposed to attackers leveraging this flaw.

Affected Version(s)

Ghost 1.18.0 < 6.27.0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

0xkakash1
0xBassia
l3tchupkt
rooks00
Wernerina
.