Server-Side Request Forgery in Ghost Content Management System
CVE-2026-70591

4.1MEDIUM

Key Information:

Vendor

Tryghost

Status
Vendor
CVE Published:
4 August 2026

What is CVE-2026-70591?

A vulnerability in the Ghost content management system allows staff-level users to exploit a Server-Side Request Forgery (SSRF) in the image fetching feature. This security flaw, present in versions 0.10.0 to 6.54.1, enables unauthorized internal HTTP GET requests, potentially allowing sensitive internal hosts to be probed for open ports. The issue was addressed in version 6.54.1, underscoring the importance of maintaining updated software to safeguard against such vulnerabilities.

Affected Version(s)

Ghost >= 0.10.0, < 6.54.1

References

CVSS V3.1

Score:
4.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.