CVE-2026-70595Medium· 4.0▾ SunlitGhost is a Node.js content management system. From 6.26.0 until 6.54.1, a validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP requests to hosts in the Ghost serve…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 22 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 6.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
Last analysed / modified upstream
Ghost is a Node.js content management system. From 6.26.0 until 6.54.1, a validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP requests to hosts in the Ghost server's internal network. A successful attack would not result in any response data being returned. This vulnerability is fixed in 6.54.1.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
ghost >= 6.26.0, < 6.54.1Patched in:
ghost 6.54.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-53944Medium· 5.8Ghost: Private IP filtering bypass to make server-side requests to internal services
CVE-2026-53945Medium· 4.0Ghost: Server-side request forgery via DNS rebinding in external request handling
CVE-2026-53946Medium· 5.4Ghost: Mobiledoc image-size fetch SSRF
CVE-2026-70591Medium· 4.1Ghost is a Node.js content management system
CVE-2026-70596Medium· 4.3Ghost is a Node.js content management system
CVE-2026-53949Medium· 5.3Ghost Content API filter bypass reveals private fields