---
id: CVE-2026-25552
title: >-
  Ghost CLI before 1.30.1 contains an IP spoofing vulnerability that allows
  unauthenticated remote attackers to bypass rate-limiting controls by
  manipulating the X-Forwarded-For header through a misconfigured Nginx
  configuration
summary: >-
  Ghost CLI before 1.30.1 contains an IP spoofing vulnerability that allows
  unauthenticated remote attackers to bypass rate-limiting controls by
  manipulating the X-Forwarded-For header through a misconfigured Nginx
  configuration. Attackers…
severity: low
cvss: 3.7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-348
published: '2026-07-31'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T20:35:08.537'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-25552'
references:
  - url: >-
      https://github.com/TryGhost/Ghost-CLI/security/advisories/GHSA-wjx2-9fpq-8997
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/ghost-cli-ip-spoofing-via-x-forwarded-for-header
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00173
epssPercentile: 0.07044
ingestedAt: '2026-09-09T21:22:45.520Z'
---

## Overview

Ghost CLI before 1.30.1 contains an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass rate-limiting controls by manipulating the X-Forwarded-For header through a misconfigured Nginx configuration. Attackers can append attacker-controlled values to the header chain using the $proxy_add_x_forwarded_for directive to present an arbitrary IP address, circumventing Ghost's rate-limiting mechanisms on self-hosted instances.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
