Low severity2.7NVD Advisory· Published Jan 10, 2026· Updated Apr 29, 2026
CVE-2026-22597
CVE-2026-22597
Description
Ghost is a Node.js content management system. In versions 5.38.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost’s media inliner mechanism allows staff users in possession of a valid authentication token for the Ghost Admin API to exfiltrate data from internal systems via SSRF. This issue has been patched in versions 5.130.6 and 6.11.0.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
ghostnpm | >= 6.0.0, < 6.11.0 | 6.11.0 |
ghostnpm | >= 5.105.0, < 5.130.6 | 5.130.6 |
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- github.com/TryGhost/Ghost/commit/15d49131ff4aac3aca8642501c793f01f2bfcbb9nvdPatchWEB
- github.com/TryGhost/Ghost/commit/93add549ccf079d8e28bdb724fbb71a76942ff51nvdPatchWEB
- github.com/TryGhost/Ghost/security/advisories/GHSA-vmc4-9828-r48rnvdPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-vmc4-9828-r48rghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-22597ghsaADVISORY
News mentions
0No linked articles in our index yet.