---
id: CVE-2026-103287
title: >-
  Ghost versions 1.18.0 before 6.27.0 contain a server-side request forgery
  vulnerability in the webhooks feature that allows staff users to probe
  internal hosts
summary: >-
  Ghost versions 1.18.0 before 6.27.0 contain a server-side request forgery
  vulnerability in the webhooks feature that allows staff users to probe
  internal hosts. Attackers with staff privileges can craft webhook requests to
  access interna…
severity: low
cvss: 2.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-918
vendor: TryGhost
product: Ghost
affected:
  - Ghost >= 1.18.0 < 6.27.0
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T11:17:25.040'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103287'
references:
  - url: 'https://github.com/TryGhost/Ghost/security/advisories/GHSA-354h-gmhv-mr9c'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/ghost-1.18.0-before-6.27.0-server-side-request-forgery-via-webhook
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-01T11:42:53.813Z'
---

## Overview

Ghost versions 1.18.0 before 6.27.0 contain a server-side request forgery vulnerability in the webhooks feature that allows staff users to probe internal hosts. Attackers with staff privileges can craft webhook requests to access internal network resources from the Ghost server.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
