CVE-2026-105647: Tryghost Ghost

Medium severity, CVSS 4.0. EPSS: 0.2% chance of exploitation in the next 30 days.

Ghost is a Node.js content management system. From 6.54.1 until 6.65.0, a validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP requests to hosts in the Ghost server's internal network. A successful attack would not result in any response data being returned. This issue is fixed in version 6.65.0.

Affected products

  • Tryghost Ghost: from 6.54.1, before 6.65.0 (fixed in 6.65.0)

Published 2026-10-05. Last modified 2026-10-06.