github.com
https://github.com/TryGhost/Ghost CVE-2026-70591
MEDIUM
Ghost: Server-Side Request Forgery in Image Fetching
Record summary
CVE-2026-70591 has a selected CVSS score of 4.1 (medium).
Description
Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a Server-Side Request Forgery in Ghost Admin image fetching allowed any staff-level user to perform a blind HTTP GET request against internal hosts. No output was returned, but this could have been used to probe open ports on internal hosts. This issue is fixed in version 6.54.1.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 5, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | >= 0.10.0, < 6.54.1 | affected | |
ghostBrowse npm / ghost | GitHub Advisory | 0.10.0 to < 6.54.1 · Fixed in 6.54.1 | affected |
References
4github.com
https://github.com/TryGhost/Ghost/commit/5eff2de0f477b11c88f20bceb9d184c0d3b8a62e github.com
https://github.com/TryGhost/Ghost/releases/tag/v6.54.1 github.comConfirmation
https://github.com/TryGhost/Ghost/security/advisories/GHSA-gcvv-72q8-9v76