Executive brief
Ghost is a popular open-source blogging and content management platform. A vulnerability in Ghost's oEmbed bookmark feature allows staff users to make unauthorized requests to internal systems and exfiltrate sensitive data, potentially exposing internal network resources, credentials, and other confidential information.
Technical details
The vulnerability is a Server Side Request Forgery (SSRF) flaw in Ghost's oEmbed bookmark mechanism (CWE-918). The vulnerable component allows authenticated staff users to craft oEmbed bookmark requests that cause the Ghost server to fetch URLs pointing to internal systems, bypassing network-level access controls. The attack requires staff-level privileges and network-level access to the Ghost instance, but does not require user interaction. An attacker with staff access can exfiltrate data from internal systems including local services, private networks, and cloud metadata services. Patches are available in Ghost v5.130.4 and v6.0.9.
Affected products
- Ghost Ghost 5.99.0 to 5.130.3, 6.0.0 to 6.0.8
Timeline
- 2025-09-15: disclosed
- 2025-09-15: patched: v5.130.4 and v6.0.9