Sceawere

Vulnerability Detail

CVE-2026-105682UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Ghost Webhooks SSRF Vulnerability

Vulnerability Metadata

Severity
Low
Score / CVSS
2.7
Creation Date
1h ago
Vendor
TryGhost
Product
Ghost
Attack Type
CWE-918: Server-Side Request Forgery (SSRF)
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Ghost is a Node.js content management system. From 1.18.0 until 6.27.0, an SSRF vulnerability in the webhooks feature allowed staff users to probe internal hosts from the Ghost server. This issue is fixed in version 6.27.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "2.7",
  "pubDate": "2026-10-05T20:17:16.647Z",
  "pubdate": "2026-10-05T20:17:16.647Z",
  "executiveSummary": "A Server-Side Request Forgery (SSRF) vulnerability exists within the webhooks feature of the Ghost content management system, affecting versions 1.18.0 through 6.27.0.\nThis security flaw enables authenticated staff users to manipulate the server into performing unauthorized HTTP requests to arbitrary internal network resources.\nThe vulnerability poses significant risk to internal infrastructure by potentially allowing an attacker to bypass perimeter security controls, scan internal services, access metadata endpoints, or interact with non-publicly exposed backend components.\nSuccessful exploitation requires staff-level authentication, limiting the threat to authorized users or compromised accounts. By leveraging the server's identity, an attacker can exfiltrate sensitive data or interact with internal APIs that are otherwise unreachable from the internet.\nThe issue has been resolved in version 6.27.0, and immediate patching is recommended for all affected instances to prevent potential exploitation.",
  "technicalDetails": "The vulnerability resides in the webhooks mechanism within Ghost, which failed to adequately validate or restrict the destination URLs provided during the webhook configuration process. This allows a staff user to define an arbitrary webhook endpoint that points to internal network addresses, such as localhost (127.0.0.1) or internal IP ranges (e.g., 10.x.x.x, 192.168.x.x).\nWhen a trigger event occurs, the Ghost server initiates an outbound HTTP request to the attacker-supplied URL using the server's own network context. Because the request originates from the Ghost server, it is often trusted by other internal services that lack secondary authentication, allowing the attacker to interact with sensitive internal resources or services.\nThe attack flow begins with a staff user configuring a malicious webhook via the Ghost administrative dashboard or API. The user supplies a target URL targeting a sensitive internal service or metadata endpoint (e.g., cloud provider instance metadata services at 169.254.169.254). Upon triggering the webhook event, the underlying Node.js application process executes the request, effectively serving as an SSRF proxy.\nThis vulnerability is particularly dangerous in cloud-hosted environments where the Ghost server might have access to sensitive Instance Metadata Service (IMDS) endpoints. By targeting these endpoints, an attacker could potentially retrieve security credentials or environment variables associated with the server instance.\nThe technical impact includes the ability to perform reconnaissance of internal networks, bypass firewalls that enforce ingress filtering but trust internal traffic, and potentially interact with internal management consoles or APIs that provide no authentication for internal traffic. Since the application fails to perform strict allow-listing or domain validation, it remains susceptible to various bypass techniques, such as DNS rebinding or the use of URL encoding to obfuscate the destination.\nThis issue affects versions 1.18.0 through 6.27.0. The vulnerability is mitigated by the introduction of robust URL validation logic in version 6.27.0, which likely includes the enforcement of destination allow-lists and the blocking of private, loopback, and link-local address spaces."
}
CVE-2026-105682: Ghost Webhooks SSRF Vulnerability (LOW Severity, CVSS: 2.7) | Sceawere