---
id: CVE-2026-105648
title: Ghost is a Node.js content management system
summary: >-
  Ghost is a Node.js content management system. From 6.0.9 until 6.65.0, a
  validation issue allowed some functionality, such as Webmentions, to be abused
  by an unauthenticated user to make limited HTTP requests to hosts in the Ghost
  server…
severity: medium
cvss: 4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N'
cwe:
  - CWE-184
  - CWE-918
vendor: TryGhost
product: Ghost
affected:
  - 'Ghost >= 6.0.9, < 6.65.0'
published: '2026-10-05'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T20:17:13.420'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105648'
references:
  - url: >-
      https://github.com/TryGhost/Ghost/commit/20d3f792bf4a7c349ee56b746a067550d8684ff5
    label: security-advisories@github.com
  - url: 'https://github.com/TryGhost/Ghost/pull/30917'
    label: security-advisories@github.com
  - url: 'https://github.com/TryGhost/Ghost/releases/tag/v6.65.0'
    label: security-advisories@github.com
  - url: 'https://github.com/TryGhost/Ghost/security/advisories/GHSA-r7f2-6fj8-6fg2'
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-05T19:30:59.998Z'
---

## Overview

Ghost is a Node.js content management system. From 6.0.9 until 6.65.0, a validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP requests to hosts in the Ghost server's internal network on some network configurations. A successful attack would not result in any response data being returned. This issue is fixed in version 6.65.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
