CVE-2025-9862: Ghost

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Server-Side Request Forgery (SSRF) vulnerability in Ghost allows an attacker to access internal resources.This issue affects Ghost: from 6.0.0 through 6.0.8, from 5.99.0 through 5.130.3.

Affected products

  • Ghost Ghost: from 5.99.0, up to and including 5.130.3; from 6.0.0, up to and including 6.0.8

Published 2025-09-17. Last modified 2026-06-17.