PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-103287 TryGhost CVE debrief

A Server-Side Request Forgery (SSRF) vulnerability was found in the webhooks feature of Ghost, allowing staff users to probe internal hosts from the Ghost server. The vulnerability affects Ghost versions from 1.18.0 up to 6.27.0. A fix is available in version 6.27.0. This SSRF vulnerability allows staff users to probe internal hosts, potentially leading to unauthorized internal host discovery. Defenders should assess exposure and prioritize updating to version 6.27.0 or later. The vulnerability was responsibly disclosed by multiple contributors.

Vendor
TryGhost
Product
ghost
CVSS
MEDIUM 5.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders responsible for Ghost installations, particularly self-hosted instances, should assess exposure and prioritize updating to version 6.27.0 or later. This includes reviewing and updating self-hosted Docker-based Ghost instances, monitoring internal hosts for potential probing attempts, and verifying affected versions and exposure. Security teams should track exceptions, retest remediated assets, and close the item only after evidence is documented.

Why it matters

CVE-2026-103287 is a Server-Side Request Forgery (SSRF) vulnerability in Ghost's webhooks feature. Staff users can exploit this to probe internal hosts. The vulnerability affects Ghost versions 1.18.0 to 6.27.0, with a fix in 6.27.0. Defenders should prioritize updates and monitor for potential probing attempts.

  • Staff users may be able to probe internal hosts
  • Potential for unauthorized internal host discovery
  • Requires verification of affected versions and exposure
  • Update priority for Ghost installations

Technical summary

The SSRF vulnerability in Ghost's webhooks feature allows staff users to probe internal hosts. The vulnerability is present in Ghost versions from 1.18.0 up to 6.27.0 and is fixed in version 6.27.0. This vulnerability can lead to potential probing attempts and unauthorized internal host discovery. Defenders should prioritize updating Ghost to version 6.27.0 or later to mitigate this SSRF vulnerability. Self-hosters using Docker should update their Ghost instance according to the official documentation. The vulnerability was responsibly disclosed, and defenders should review the CVE record and NVD entry for additional details.

Defensive priority

Defenders should prioritize updating Ghost to version 6.27.0 or later to mitigate this SSRF vulnerability. Self-hosters using Docker should update their Ghost instance according to the official documentation.

Recommended defensive actions

  • Update Ghost to version 6.27.0 or later
  • Review and update self-hosted Docker-based Ghost instances
  • Monitor internal hosts for potential probing attempts
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The vulnerability was responsibly disclosed by multiple contributors, including 0xkakash1, rooks00, l3tchupkt, Wernerina, [email protected], and Mohamed Bassia. The CVE record and NVD entry provide additional details. Evidence is limited to public sources and may not be comprehensive. Defenders should verify affected versions and exposure.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-103287 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-103287

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-103287 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-103287

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Ghost: Server-Side Request Forgery in Webhook Trigger

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-354h-gmhv-mr9c.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://github.com/TryGhost/Ghost/security/advisories/GHSA-354h-gmhv-mr9c

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105682

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/TryGhost/Ghost/issues/27219

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/TryGhost/Ghost/commit/815962dd2760e55c5dc8d0fb7fac732a7634566f

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/TryGhost/Ghost

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/TryGhost/Ghost/releases/tag/v6.27.0

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.