CVE-2026-70591 Details
Description
Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a Server-Side Request Forgery in Ghost Admin image fetching allowed any staff-level user to perform a blind HTTP GET request against internal hosts. No output was returned, but this could have been used to probe open ports on internal hosts. This issue is fixed in version 6.54.1.
A server-side request forgery (SSRF) vulnerability has been identified in Ghost, a Node.js content management system. This issue affects Ghost versions 0.10.0 prior to 6.54.1. The vulnerability allows any staff-level user to perform a blind HTTP GET request to internal hosts via the Ghost Admin image fetching feature. While no output is returned, this could be exploited to probe open ports on internal systems.
Users can update to Ghost version 6.54.1, which includes a fix for this vulnerability. For self-hosters using Docker, instructions for updating a Docker-based Ghost instance are available in the Ghost documentation. If Ghost was installed using Ghost-CLI, see the Ghost documentation on updating to the latest version.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 4, 2026CISA-ADP
Assessed Aug 5, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/TryGhost/Ghost/commit/5eff2de0f477b11c88f20bceb9d184c0d3b8a62e | [email protected] | Source CodeVendor |
| https://github.com/TryGhost/Ghost/releases/tag/v6.54.1 | [email protected] | Release NotesVendor |
| https://github.com/TryGhost/Ghost/security/advisories/GHSA-gcvv-72q8-9v76 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Ghost | >= 0.10.0, < 6.54.1 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 5, 2026 | CVE Modified | CISA-ADP |
| Aug 4, 2026 | New CVE Received | [email protected] |
Volerion