PT-2026-52068 · Ghost · Ghost

CVE-2026-53944

·

Published

2026-06-24

·

Updated

2026-08-04

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Ghost versions 6.0.9 through 6.21.0
Description Ghost is a Node.js content management system. An issue exists where the IP filter designed to prevent external requests from reaching internal services can be bypassed. This is achieved by using an IPv6 literal that maps to a private IPv4 address.
Recommendations Update Ghost to version 6.21.1.

Exploit

Fix

SSRF

Incomplete List of Disallowed Inputs

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-GHOST-2026-53944
CVE-2026-53944
GHSA-WVP2-4QQP-4H3R

Affected Products

Ghost