Junglewise Threat Intelligence

CVE-2026-53944: TryGhost Ghost SSRF via IPv6 private IP filter bypass

CVE-2026-53944 · Severity: medium · CVSS 5.8 · Published 2026-06-24

Technologies: ghost (npm). Vendors: npm.

Executive brief

Ghost, a popular open-source publishing platform, is vulnerable to a security bypass that allows attackers to reach internal network services. By using specially formatted web addresses, an attacker can trick the server into communicating with private internal systems that should be protected. This could allow unauthorized access to internal tools or data not intended for public exposure.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in Ghost due to an incomplete list of disallowed inputs in its IP filtering mechanism. The filter, intended to prevent requests to internal services, can be bypassed by using an IPv6 literal that maps to a private IPv4 address. This allows a remote attacker to make requests to internal network resources that are otherwise unreachable from the public internet. The vulnerability is present in versions 6.0.9 through 6.21.0 and is addressed in version 6.21.1.

Affected products

  • Ghost Foundation Ghost 6.0.9 to 6.21.0

Timeline

  • 2026-06-10: disclosed: Initial disclosure to TryGhost/Ghost
  • 2026-06-24: advisory: NVD publication date
  • 2026-08-04: patched: GitHub Advisory reviewed and updated with patch information

References

Related threats