CVE-2026-105682
Received Received - Intake

SSRF Vulnerability in Ghost CMS via Webhooks

Vulnerability report for CVE-2026-105682, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Ghost is a Node.js content management system. From 1.18.0 until 6.27.0, an SSRF vulnerability in the webhooks feature allowed staff users to probe internal hosts from the Ghost server. This issue is fixed in version 6.27.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
TryGhost Ghost >= 1.18.0, < 6.27.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Server-Side Request Forgery (SSRF) vulnerability in the Ghost CMS webhooks feature. It allowed staff users to probe internal hosts from the Ghost server. The issue affected versions from 1.18.0 to 6.27.0 and was fixed in version 6.27.0.

Detection Guidance

To detect this SSRF vulnerability in Ghost, check if your Ghost instance is running a vulnerable version (1.18.0 to 6.27.0). Verify if the `security.allowWebhookInternalIPs` configuration is set to true, which would allow webhooks to probe internal hosts. Inspect webhook logs for outbound requests to internal IP addresses.

Impact Analysis

An attacker with staff privileges could exploit this to access internal network resources, potentially exposing sensitive data or internal services. The impact is limited by the need for high privileges and the low CVSS score.

Compliance Impact

This SSRF vulnerability could potentially allow unauthorized probing of internal hosts from a Ghost server, which may expose sensitive data or internal systems. For GDPR, this could lead to unauthorized access to personal data, violating principles of data protection and security. For HIPAA, it might risk exposing protected health information if internal systems are probed.

Mitigation Strategies

Update Ghost to version 6.27.0 or later to patch the SSRF vulnerability in the webhooks feature. For self-hosted instances, especially Docker setups, follow the official documentation to upgrade. Additionally, review and set the security.allowWebhookInternalIPs configuration option to false (default) to block webhooks from reaching internal IP addresses unless explicitly required.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105682. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart