PatchSiren cyber security CVE debrief
CVE-2026-103287 TryGhost CVE debrief
A Server-Side Request Forgery (SSRF) vulnerability was found in the webhooks feature of Ghost, allowing staff users to probe internal hosts from the Ghost server. The vulnerability affects Ghost versions from 1.18.0 up to 6.27.0. A fix is available in version 6.27.0. This SSRF vulnerability allows staff users to probe internal hosts, potentially leading to unauthorized internal host discovery. Defenders should assess exposure and prioritize updating to version 6.27.0 or later. The vulnerability was responsibly disclosed by multiple contributors.
- Vendor
- TryGhost
- Product
- ghost
- CVSS
- MEDIUM 5.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for Ghost installations, particularly self-hosted instances, should assess exposure and prioritize updating to version 6.27.0 or later. This includes reviewing and updating self-hosted Docker-based Ghost instances, monitoring internal hosts for potential probing attempts, and verifying affected versions and exposure. Security teams should track exceptions, retest remediated assets, and close the item only after evidence is documented.
Why it matters
CVE-2026-103287 is a Server-Side Request Forgery (SSRF) vulnerability in Ghost's webhooks feature. Staff users can exploit this to probe internal hosts. The vulnerability affects Ghost versions 1.18.0 to 6.27.0, with a fix in 6.27.0. Defenders should prioritize updates and monitor for potential probing attempts.
- Staff users may be able to probe internal hosts
- Potential for unauthorized internal host discovery
- Requires verification of affected versions and exposure
- Update priority for Ghost installations
Technical summary
The SSRF vulnerability in Ghost's webhooks feature allows staff users to probe internal hosts. The vulnerability is present in Ghost versions from 1.18.0 up to 6.27.0 and is fixed in version 6.27.0. This vulnerability can lead to potential probing attempts and unauthorized internal host discovery. Defenders should prioritize updating Ghost to version 6.27.0 or later to mitigate this SSRF vulnerability. Self-hosters using Docker should update their Ghost instance according to the official documentation. The vulnerability was responsibly disclosed, and defenders should review the CVE record and NVD entry for additional details.
Defensive priority
Defenders should prioritize updating Ghost to version 6.27.0 or later to mitigate this SSRF vulnerability. Self-hosters using Docker should update their Ghost instance according to the official documentation.
Recommended defensive actions
- Update Ghost to version 6.27.0 or later
- Review and update self-hosted Docker-based Ghost instances
- Monitor internal hosts for potential probing attempts
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The vulnerability was responsibly disclosed by multiple contributors, including 0xkakash1, rooks00, l3tchupkt, Wernerina, [email protected], and Mohamed Bassia. The CVE record and NVD entry provide additional details. Evidence is limited to public sources and may not be comprehensive. Defenders should verify affected versions and exposure.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-103287 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-103287
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-103287 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-103287
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Ghost: Server-Side Request Forgery in Webhook Trigger
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-354h-gmhv-mr9c.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/TryGhost/Ghost/security/advisories/GHSA-354h-gmhv-mr9c
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105682
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/TryGhost/Ghost/issues/27219
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/TryGhost/Ghost/commit/815962dd2760e55c5dc8d0fb7fac732a7634566f
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/TryGhost/Ghost
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/TryGhost/Ghost/releases/tag/v6.27.0
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.