github.com
https://github.com/TryGhost/Ghost CVE-2026-70595
MEDIUM
Ghost: Server-Side Request Forgery Mitigation Issue
Record summary
CVE-2026-70595 has a selected CVSS score of 4.0 (medium).
Description
Ghost is a Node.js content management system. From 6.26.0 until 6.54.1, a validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP requests to hosts in the Ghost server's internal network. A successful attack would not result in any response data being returned. This vulnerability is fixed in 6.54.1.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 6, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | >= 6.26.0, < 6.54.1 | affected | |
ghostBrowse npm / ghost | GitHub Advisory | 6.26.0 to < 6.54.1 · Fixed in 6.54.1 | affected |
References
2github.comConfirmation
https://github.com/TryGhost/Ghost/security/advisories/GHSA-x5mm-wm4g-j5xv