Server-Side Request Forgery Vulnerability in Ghost Product by Ghost Foundation
CVE-2026-103291

5.3MEDIUM

Key Information:

Vendor

Tryghost

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-103291?

The Ghost product versions from 3.20.2 prior to 6.51.0 exhibit a server-side request forgery vulnerability within the image dimension refetching mechanism. This flaw enables authenticated staff users to initiate outbound HTTP requests to arbitrary URLs. Consequently, attackers could exploit this vulnerability by directing image cards to attacker-controlled hosts or internal network endpoints, allowing access to sensitive metadata services and internal resources that are typically not accessible from the public internet.

Affected Version(s)

Ghost 3.20.2 < 6.51.0

Ghost 6.51.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.