Junglewise Threat Intelligence

CVE-2025-9862: Ghost Server Side Request Forgery in oEmbed Bookmark

CVE-2025-9862 · Severity: medium · CVSS 4 · Published 2025-09-15

Vendors: Ghost.

Executive brief

Ghost is a popular open-source blogging and content management platform. A vulnerability in Ghost's oEmbed bookmark feature allows staff users to make unauthorized requests to internal systems and exfiltrate sensitive data, potentially exposing internal network resources, credentials, and other confidential information.

Technical details

The vulnerability is a Server Side Request Forgery (SSRF) flaw in Ghost's oEmbed bookmark mechanism (CWE-918). The vulnerable component allows authenticated staff users to craft oEmbed bookmark requests that cause the Ghost server to fetch URLs pointing to internal systems, bypassing network-level access controls. The attack requires staff-level privileges and network-level access to the Ghost instance, but does not require user interaction. An attacker with staff access can exfiltrate data from internal systems including local services, private networks, and cloud metadata services. Patches are available in Ghost v5.130.4 and v6.0.9.

Affected products

  • Ghost Ghost 5.99.0 to 5.130.3, 6.0.0 to 6.0.8

Timeline

  • 2025-09-15: disclosed
  • 2025-09-15: patched: v5.130.4 and v6.0.9

References