CVE-2026-105682
LOW
NVD
CVSS Score
2.7
Severity
LOW
Published
Oct 05, 2026
Vendor
unknown
Description
Ghost is a Node.js content management system. From 1.18.0 until 6.27.0, an SSRF vulnerability in the webhooks feature allowed staff users to probe internal hosts from the Ghost server. This issue is fixed in version 6.27.0.