Junglewise Threat Intelligence

CVE-2026-22597: Ghost SSRF via External Media Inliner

CVE-2026-22597 · Severity: medium · CVSS 4 · Published 2026-01-08

Vendors: Ghost.

Executive brief

Ghost, a popular open-source publishing platform, contains a server-side request forgery (SSRF) vulnerability in its media inlining feature. Authenticated staff users with API access can exploit this to probe and exfiltrate data from internal systems that would otherwise be inaccessible from the internet, potentially exposing sensitive infrastructure information or internal APIs.

Technical details

This SSRF vulnerability exists in Ghost's media inliner mechanism and requires a valid authentication token for the Ghost Admin API, restricting exploitation to staff users. The vulnerability allows attackers to make arbitrary HTTP requests to internal systems by manipulating media inlining parameters, bypassing network-level access controls. Attack vector is network-based with low complexity and no user interaction required once authenticated. Patches are available in Ghost v5.130.6 and v6.11.0. The vulnerability affects versions 5.38.0–5.130.5 and 6.0.0–6.10.3.

Affected products

  • Ghost Ghost 5.38.0 to 5.130.5, 6.0.0 to 6.10.3

Timeline

  • 2026-01-08: disclosed: Vulnerability published by Ghost security team
  • 2026-01-08: patched: Patches released in versions 5.130.6 and 6.11.0

References