CVE-2026-105682: Ghost: Server-Side Request Forgery in Webhook Trigger
Ghost is a Node.js content management system. From 1.18.0 until 6.27.0, an SSRF vulnerability in the webhooks feature allowed staff users to probe internal hosts from the Ghost server. This issue is fixed in version 6.27.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ghostto a version that resolves this vulnerability.Fixed in 6.27.0
Event History
Frequently Asked Questions
Who can exploit this issue?
A staff user who can use the Ghost webhooks feature can exploit the issue. The SSRF requests originate from the Ghost server, allowing that user to probe hosts reachable from the server's network.
Which deployments are affected?
Ghost versions from 1.18.0 up to, but not including, 6.27.0 are affected. Version 6.27.0 fixes the issue.
What should be done if upgrading cannot happen immediately?
Limit access to staff accounts and the webhooks feature to trusted users, since staff users can trigger the vulnerable behavior. Restricting the Ghost server's network access can also reduce the internal hosts it can reach.