---
id: CVE-2026-105682
title: Ghost is a Node.js content management system
summary: >-
  Ghost is a Node.js content management system. From 1.18.0 until 6.27.0, an
  SSRF vulnerability in the webhooks feature allowed staff users to probe
  internal hosts from the Ghost server. This issue is fixed in version 6.27.0.
severity: low
cvss: 2.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-918
vendor: TryGhost
product: Ghost
affected:
  - 'Ghost >= 1.18.0, < 6.27.0'
published: '2026-10-05'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T20:17:16.647'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105682'
references:
  - url: >-
      https://github.com/TryGhost/Ghost/commit/815962dd2760e55c5dc8d0fb7fac732a7634566f
    label: security-advisories@github.com
  - url: 'https://github.com/TryGhost/Ghost/issues/27219'
    label: security-advisories@github.com
  - url: 'https://github.com/TryGhost/Ghost/releases/tag/v6.27.0'
    label: security-advisories@github.com
  - url: 'https://github.com/TryGhost/Ghost/security/advisories/GHSA-354h-gmhv-mr9c'
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-05T20:32:56.649Z'
---

## Overview

Ghost is a Node.js content management system. From 1.18.0 until 6.27.0, an SSRF vulnerability in the webhooks feature allowed staff users to probe internal hosts from the Ghost server. This issue is fixed in version 6.27.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
