CVE-2026-53946
published 2026-06-24CVE-2026-53946: Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, when re-rendering posts, Ghost would refetch missing image dimensions by issuing an…
PriorityP430medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.21%
9.8th percentile
Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, when re-rendering posts, Ghost would refetch missing image dimensions by issuing an outbound HTTP request to the URL stored on an image card — without restricting that URL to trusted image hosts. An authenticated staff user able to create or edit posts could therefore point an image card at an attacker-chosen host and cause the Ghost server to request it on their behalf, including hosts on internal networks or cloud instance metadata endpoints that would not normally be reachable from the public internet. This vulnerability is fixed in 6.21.1.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ghost | ghost | >= 6.19.4 < 6.21.2 | 6.21.2 |
| tryghost | ghost | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Ghost: Mobiledoc image-size fetch SSRF
ghsa·2026-08-04
CVE-2026-53946 [MEDIUM] CWE-918 Ghost: Mobiledoc image-size fetch SSRF
Ghost: Mobiledoc image-size fetch SSRF
### Impact
When re-rendering posts, Ghost would refetch missing image dimensions by issuing an outbound HTTP request to the URL stored on an image card — without restricting that URL to trusted image hosts. An authenticated staff user able to create or edit posts could therefore point an image card at an attacker-chosen host and cause the Ghost server to request it on their behalf, including hosts on internal networks or cloud instance metadata endpoints that would not normally be reachable from the public internet.
### Vulnerable versions
This vulnerability is present in Ghost from v6.19.3 up to v6.21.0.
### Patches
v6.21.1 contains a fix for this issue.
### How to update
For self-hosters using Docker, find [Docker's official Ghost image here
VulDB
TryGhost up to 6.21.0 HTTP Request server-side request forgery (GHSA-g366-23fw-ggp6)
vuldb·2026-06-24·CVSS 5.4
CVE-2026-53946 [MEDIUM] TryGhost up to 6.21.0 HTTP Request server-side request forgery (GHSA-g366-23fw-ggp6)
A vulnerability was found in TryGhost Ghost up to 6.21.0. It has been classified as critical. The affected element is an unknown function of the component HTTP Request Handler. The manipulation leads to server-side request forgery.
This vulnerability is documented as CVE-2026-53946. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-24
Published