PT-2026-2219 · Ghost · Ghost

Odgrso

·

Published

2026-01-08

·

Updated

2026-01-10

·

CVE-2026-22597

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Ghost versions 5.38.0 through 5.130.5 Ghost versions 6.0.0 through 6.10.3
Description Ghost is a Node.js content management system. A flaw in Ghost’s media inliner mechanism enables staff users with a valid authentication token for the Ghost Admin API to extract data from internal systems through Server-Side Request Forgery (SSRF). SSRF occurs when a server is tricked into making requests to unintended locations, potentially exposing internal resources.
Recommendations Update to Ghost version 5.130.6 or later. Update to Ghost version 6.11.0 or later.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

BIT-GHOST-2026-22597
CVE-2026-22597
GHSA-VMC4-9828-R48R

Affected Products

Ghost