CVE-2026-103287 PUBLISHED

Ghost 1.18.0 before 6.27.0 Server-Side Request Forgery via Webhook

Assigner: VulnCheck
Reserved: 30.09.2026 Published: 01.10.2026 Updated: 01.10.2026

Ghost versions 1.18.0 before 6.27.0 contain a server-side request forgery vulnerability in the webhooks feature that allows staff users to probe internal hosts. Attackers with staff privileges can craft webhook requests to access internal network resources from the Ghost server.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 5.1

Product Status

Vendor TryGhost
Product Ghost
Versions Default: unaffected
  • affected from 1.18.0 to 6.27.0 (excl.)

Credits

  • 0xkakash1 reporter
  • 0xBassia reporter
  • l3tchupkt reporter
  • rooks00 reporter
  • Wernerina reporter

References

Problem Types

  • Server-Side Request Forgery (SSRF) CWE