CVE-2026-70591
published 2026-08-04CVE-2026-70591: Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a Server-Side Request Forgery in Ghost Admin image fetching allowed any staff-level…
PriorityP420medium4.1CVSS 3.1
AVNACLPRHUINSCCLINAN
EPSS
0.37%
28.2th percentile
Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a Server-Side Request Forgery in Ghost Admin image fetching allowed any staff-level user to perform a blind HTTP GET request against internal hosts. No output was returned, but this could have been used to probe open ports on internal hosts. This issue is fixed in version 6.54.1.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ghost | ghost | >= 0.10.0 < 6.54.1 | 6.54.1 |
| tryghost | ghost | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
TryGhost up to 6.54.0 server-side request forgery
vuldb·2026-08-05·CVSS 4.1
CVE-2026-70591 [MEDIUM] TryGhost up to 6.54.0 server-side request forgery
A vulnerability described as problematic has been identified in TryGhost Ghost up to 6.54.0. This affects an unknown part. The manipulation results in server-side request forgery.
This vulnerability is reported as CVE-2026-70591. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.
GHSA
Ghost: Server-Side Request Forgery in Image Fetching
ghsa·2026-08-04
CVE-2026-70591 [MEDIUM] CWE-918 Ghost: Server-Side Request Forgery in Image Fetching
Ghost: Server-Side Request Forgery in Image Fetching
### Impact
A Server-Side Request Forgery (SSRF) in Ghost Admin allowed any staff-level user to perform a blind HTTP GET request against internal hosts. No output was returned, but this could have been used to probe open ports on internal hosts.
### Vulnerable versions
This vulnerability is present in Ghost from v0.10.0 up to v6.54.0.
### Patches
v6.54.1 contains a fix for this issue.
### How to update
For self-hosters using Docker, find [Docker's official Ghost image here](https://hub.docker.com/_/ghost). Updating a Docker-based Ghost instance [is documented here](https://docs.ghost.org/install/docker#updating-ghost).
If your Ghost is a Ghost-CLI install see our documentation on [updating it to the latest version here](https://d
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-04
Published