CVE-2025-9862: Ghost 6.0.6 - SSRF via oEmbed Bookmark
Impact
A vulnerability in Ghost's oEmbed mechanism allows staff users to exfiltrate data from internal systems via SSRF.
Vulnerable versions
This vulnerability is present in Ghost v5.99.0 to v5.130.3 to and Ghost v6.0.0 to v6.0.8.
Patches
v5.130.4 and v6.0.9 contain a fix for this issue.
References
The original report is available here: https://fluidattacks.com/advisories/regida
We thank Cristian Vargas for discovering and disclosing this vulnerability responsibly.
For more information
If you have any questions or comments about this advisory, email us at security@ghost.org.
Other sources
Server-Side Request Forgery (SSRF) vulnerability in Ghost allows an attacker to access internal resources.This issue affects Ghost: from 6.0.0 through 6.0.8, from 5.99.0 through 5.130.3.
— NVD
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9862?
CVE-2025-9862 is considered a high-severity vulnerability due to its potential for data exfiltration via SSRF.
How do I fix CVE-2025-9862?
To fix CVE-2025-9862, upgrade Ghost to version 5.130.4 or 6.0.9 or later.
What versions of Ghost are affected by CVE-2025-9862?
Ghost versions 5.99.0 to 5.130.3 and 6.0.0 to 6.0.8 are affected by CVE-2025-9862.
What kind of vulnerability is CVE-2025-9862?
CVE-2025-9862 is a Server-Side Request Forgery (SSRF) vulnerability in Ghost's oEmbed mechanism.
Can CVE-2025-9862 lead to data breaches?
Yes, CVE-2025-9862 can allow malicious users to exfiltrate data from internal systems, leading to potential data breaches.