SSRF Vulnerability in Ghost CMS Affects Versions 1.18.0 to 6.27.0
CVE-2026-105682

2.7LOW

Key Information:

Vendor

Tryghost

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-105682?

Ghost, a popular Node.js content management system, has a Server-Side Request Forgery (SSRF) vulnerability in its webhooks feature, enabling authenticated staff users to send requests to internal server resources. This can lead to unauthorized access of sensitive information within the internal network. This issue was present in Ghost versions 1.18.0 through 6.27.0 and has been addressed in version 6.27.0, which is critical for users to upgrade to in order to ensure their application’s security. For more details, please refer to the Ghost security advisory.

Affected Version(s)

Ghost >= 1.18.0, < 6.27.0

References

CVSS V3.1

Score:
2.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.