CVE-2026-105647Medium· 4.0▾ SunlitGhost is a Node.js content management system. From 6.54.1 until 6.65.0, a validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP requests to hosts in the Ghost serve…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 22 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Ghost is a Node.js content management system. From 6.54.1 until 6.65.0, a validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP requests to hosts in the Ghost server's internal network. A successful attack would not result in any response data being returned. This issue is fixed in version 6.65.0.
Ghost >= 6.54.1, < 6.65.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-105648Medium· 4.0Ghost: Private IP Filtering Bypass via IPv6 Transition Addresses
CVE-2026-53945Medium· 4.0Ghost: Server-side request forgery via DNS rebinding in external request handling
CVE-2026-105649High· 7.3Ghost: Stored XSS via SVG Uploads Bypassing Sanitization
CVE-2026-103291Medium· 6.4Ghost versions from 3.20.2 before 6.51.0 contain a server-side request forgery vulnerability in image dimension refetching that allows authenticated staff users to trigger outbound HTTP requests to arbitrary URLs
CVE-2026-103287Low· 2.7Ghost versions 1.18.0 before 6.27.0 contain a server-side request forgery vulnerability in the webhooks feature that allows staff users to probe internal hosts
CVE-2026-70595Medium· 4.0Ghost is a Node.js content management system