An SSRF vulnerability in the webhooks feature allowed staff users to probe internal hosts from the Ghost server.
This vulnerability is present in Ghost from v1.18.0 up to v6.27.0.
v6.27.0 contains a fix for this issue.
For self-hosters using Docker, find Docker's official Ghost image here. Updating a Docker-based Ghost instance is documented here.
If your Ghost is a Ghost-CLI install see our documentation on updating it to the latest version here.
Ghost thanks 0xkakash1, rooks00, l3tchupkt, Wernerina, krn0@bugcrowdninja.com, and Mohamed Bassia for disclosing this vulnerability responsibly.
If you have any questions or comments about this advisory, email us at security@ghost.org.
{
"cwe_ids": [
"CWE-918"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-07T16:17:57Z",
"nvd_published_at": "2026-10-05T20:17:16Z",
"severity": "LOW"
}