Sceawere
Vulnerability Detail
CVE-2026-105648UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Ghost Server-Side Request Forgery
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4
- Creation Date
- 1h ago
- Vendor
- TryGhost
- Product
- Ghost
- Attack Type
- CWE-184: Incomplete List of Disallowed Inputs
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Ghost is a Node.js content management system. From 6.0.9 until 6.65.0, a validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP requests to hosts in the Ghost server's internal network on some network configurations. A successful attack would not result in any response data being returned. This issue is fixed in version 6.65.0.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.0",
"pubDate": "2026-10-05T20:17:13.420Z",
"pubdate": "2026-10-05T20:17:13.420Z",
"executiveSummary": "A Server-Side Request Forgery (SSRF) vulnerability exists in the Ghost content management system, affecting versions 6.0.9 through 6.65.0.\nThe vulnerability originates from improper input validation within specific functionalities, most notably the Webmentions feature.\nThis flaw allows unauthenticated remote attackers to force the Ghost server to perform unauthorized HTTP requests to arbitrary targets within the host's internal network environment.\nWhile successful exploitation does not return response data to the attacker, the ability to interact with internal services facilitates reconnaissance and potential lateral movement against infrastructure shielded from the public internet.\nRisk is significant in network configurations where the Ghost application server has direct access to sensitive internal resources, APIs, or metadata services.\nExploitation is possible without prior authentication, requiring only the ability to reach the vulnerable endpoint, representing a notable security weakness in the application's request handling logic.",
"technicalDetails": "The vulnerability is categorized as Server-Side Request Forgery (SSRF), arising from insufficient validation of user-supplied input when the application initiates outbound network requests.\nSpecifically, the Webmentions functionality in Ghost fails to adequately sanitize or restrict the destination URLs provided during the request process.\nThe root cause lies in the application's failure to implement a robust blocklist or allowlist mechanism to filter requests targeted at local interfaces, internal IP ranges (e.g., 127.0.0.1, 192.168.x.x, 10.x.x.x), or sensitive cloud metadata services (e.g., 169.254.169.254).\nAn unauthenticated attacker can supply a crafted URL to the vulnerable feature, effectively turning the Ghost server into a proxy for arbitrary HTTP requests.\nThe attack flow proceeds as follows: 1) The attacker identifies a feature that triggers an outbound request, such as the Webmentions mechanism. 2) The attacker submits a crafted payload containing an internal target URL. 3) The Ghost server, acting as the request initiator, attempts to establish a connection to the specified internal host and port.\nBecause the application does not strictly validate the destination, it processes the request under the identity and network context of the Ghost application server.\nAlthough the current implementation design suppresses the return of response data, the request itself is executed on the target service.\nThis behavior allows an attacker to perform port scanning, interact with internal APIs that lack authentication, or trigger state-changing actions on internal services (e.g., memory cache clearing, configuration changes) that rely on IP-based trust models.\nThe vulnerability is present in versions 6.0.9 through 6.65.0. Successful exploitation relies on the server's network configuration; if the Ghost instance resides within a VPC or a segmented internal network, the impact is magnified as the attacker gains access to non-publicly routable assets.\nPost-exploitation impact includes the potential for infrastructure reconnaissance, identifying live internal hosts, and potentially disrupting internal services through unintended interactions, even in the absence of direct data exfiltration via the vulnerability itself."
}