VYPR
Moderate severityNVD Advisory· Published Sep 17, 2025· Updated Sep 17, 2025

Ghost 6.0.6 - SSRF via oEmbed Bookmark

CVE-2025-9862

Description

Server-Side Request Forgery (SSRF) vulnerability in Ghost allows an attacker to access internal resources.This issue affects Ghost: from 6.0.0 through 6.0.8, from 5.99.0 through 5.130.3.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
ghostnpm
>= 6.0.0, < 6.0.96.0.9
ghostnpm
>= 5.99.0, < 5.130.45.130.4

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

7

News mentions

0

No linked articles in our index yet.