---
id: CVE-2026-103291
title: >-
  Ghost versions from 3.20.2 before 6.51.0 contain a server-side request forgery
  vulnerability in image dimension refetching that allows authenticated staff
  users to trigger outbound HTTP requests to arbitrary URLs
summary: >-
  Ghost versions from 3.20.2 before 6.51.0 contain a server-side request forgery
  vulnerability in image dimension refetching that allows authenticated staff
  users to trigger outbound HTTP requests to arbitrary URLs. Attackers can point
  ima…
severity: medium
cvss: 6.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'
cwe:
  - CWE-918
vendor: TryGhost
product: Ghost
affected:
  - Ghost >= 3.20.2 < 6.51.0
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T11:17:25.680'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103291'
references:
  - url: 'https://github.com/TryGhost/Ghost/security/advisories/GHSA-rrq6-9r3c-7w26'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/ghost-3.20.2-before-6.51.0-ssrf-via-image-size-fetch
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-01T11:42:53.815Z'
---

## Overview

Ghost versions from 3.20.2 before 6.51.0 contain a server-side request forgery vulnerability in image dimension refetching that allows authenticated staff users to trigger outbound HTTP requests to arbitrary URLs. Attackers can point image cards at attacker-controlled hosts or internal network endpoints to access metadata services and internal resources unavailable from the public internet.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
