CVE-2026-70595: Tryghost Ghost
Medium severity, CVSS 4.0. EPSS: 0.3% chance of exploitation in the next 30 days.
Ghost is a Node.js content management system. From 6.26.0 until 6.54.1, a validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP requests to hosts in the Ghost server's internal network. A successful attack would not result in any response data being returned. This vulnerability is fixed in 6.54.1.
Affected products
- Tryghost Ghost: from 6.26.0, before 6.54.1 (fixed in 6.54.1)
Published 2026-08-05. Last modified 2026-09-08.