Server-Side Request Forgery (SSRF) vulnerability in Ghost allows an attacker to access internal resources.This issue affects Ghost: from 6.0.0 through 6.0.8, from 5.99.0 through 5.130.3.
References
| Link | Resource |
|---|---|
| https://fluidattacks.com/advisories/regida | Exploit Third Party Advisory |
| https://github.com/TryGhost/Ghost | Product |
| https://github.com/TryGhost/Ghost/releases/tag/v6.0.9 | Patch |
| https://github.com/TryGhost/Ghost/security/advisories/GHSA-f7qg-xj45-w956 | Third Party Advisory |
| https://fluidattacks.com/advisories/regida | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
29 Jan 2026, 01:54
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Ghost
Ghost ghost |
|
| CPE | cpe:2.3:a:ghost:ghost:*:*:*:*:*:node.js:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
| References | () https://fluidattacks.com/advisories/regida - Exploit, Third Party Advisory | |
| References | () https://github.com/TryGhost/Ghost - Product | |
| References | () https://github.com/TryGhost/Ghost/releases/tag/v6.0.9 - Patch | |
| References | () https://github.com/TryGhost/Ghost/security/advisories/GHSA-f7qg-xj45-w956 - Third Party Advisory | |
| Summary |
|
17 Sep 2025, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://fluidattacks.com/advisories/regida - |
17 Sep 2025, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-09-17 15:15
Updated : 2026-02-24 18:36
NVD link : CVE-2025-9862
Mitre link : CVE-2025-9862
CVE.ORG link : CVE-2025-9862
JSON object : View
Products Affected
ghost
- ghost
CWE
CWE-918
Server-Side Request Forgery (SSRF)
