PT-2026-52068 · Ghost · Ghost
CVE-2026-53944
·
Published
2026-06-24
·
Updated
2026-08-04
CVSS v3.1
5.8
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Ghost versions 6.0.9 through 6.21.0
Description
Ghost is a Node.js content management system. An issue exists where the IP filter designed to prevent external requests from reaching internal services can be bypassed. This is achieved by using an IPv6 literal that maps to a private IPv4 address.
Recommendations
Update Ghost to version 6.21.1.
Exploit
Fix
SSRF
Incomplete List of Disallowed Inputs
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ghost