PT-2026-52069 · Ghost · Ghost

CVE-2026-53945

·

Published

2026-06-24

·

Updated

2026-08-04

CVSS v3.1

4.0

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Ghost versions 6.0.9 through 6.21.0
Description Ghost is a Node.js content management system. A flaw in the private-IP check for outbound HTTP requests allows a bypass via DNS rebinding. DNS rebinding is a technique that tricks a browser or server into accessing a private network address by changing the DNS record of a domain after the initial check. This allows an attacker to force the server to reach hosts on internal networks through features that perform external fetches.
Recommendations Update to version 6.21.1.

Exploit

Fix

Time Of Check To Time Of Use

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-GHOST-2026-53945
CVE-2026-53945
GHSA-CH52-PX8Q-F22J

Affected Products

Ghost