PT-2025-37860 · Ghost · Ghost

Cristian Vargas

·

Published

2025-09-15

·

Updated

2026-02-24

·

CVE-2025-9862

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Ghost versions 5.99.0 through 5.130.3 Ghost versions 6.0.0 through 6.0.8
Description A Server-Side Request Forgery (SSRF) vulnerability exists in Ghost that allows an attacker to access internal resources. The vulnerability is present in Ghost’s oEmbed mechanism and allows staff users to exfiltrate data from internal systems via SSRF.
Recommendations Update to Ghost version 5.130.4 or later. Update to Ghost version 6.0.9 or later.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

BIT-GHOST-2025-9862
CVE-2025-9862
GHSA-F7QG-XJ45-W956

Affected Products

Ghost