CVE-2026-22597

LOW

Ghost < 5.130.6 - SSRF

Title source: rule
STIX 2.1

Description

Ghost is a Node.js content management system. In versions 5.38.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost’s media inliner mechanism allows staff users in possession of a valid authentication token for the Ghost Admin API to exfiltrate data from internal systems via SSRF. This issue has been patched in versions 5.130.6 and 6.11.0.

Scores

CVSS v3 2.7
EPSS 0.0006
EPSS Percentile 17.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (2)
ghost/ghost 5.38.0 - 5.130.6
npm/ghost 6.0.0 - 6.11.0npm
Published Jan 10, 2026
Tracked Since Feb 18, 2026