DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-105647: CVE-2026-105647: Server-Side Request Forgery via Favicon Probing in Ghost CMS

CVE-2026-105647: Server-Side Request Forgery via Favicon Probing in Ghost CMS

Vulnerability ID: CVE-2026-105647
CVSS Score: 4.0
Published: 2026-10-07

An unauthenticated Server-Side Request Forgery (SSRF) vulnerability exists in Ghost CMS from version 6.54.1 to 6.65.0. The vulnerability stems from a validation bypass in the favicon resolution logic within the bookmark-fetching subsystem, which allows remote, unauthenticated attackers to trigger arbitrary HTTP requests to the local host and internal networks. This bypass circumvents the custom DNS-level IP blocklist controls configured globally in the application.

TL;DR

Ghost CMS versions 6.54.1 through 6.64.0 are vulnerable to unauthenticated blind SSRF due to a validation bypass in the favicon resolution flow. Attackers can leverage this to make HTTP requests targeting private and loopback networks.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-918 / CWE-367
  • Attack Vector: Network
  • CVSS v3.1 Score: 4.0 (Medium)
  • Exploit Status: PoC / Analytical
  • CISA KEV Status: Not Listed
  • Impact: Low Confidentiality (Blind SSRF)

Affected Systems

  • Ghost Content Management System (CMS)
  • Ghost: >= 6.54.1, < 6.65.0 (Fixed in: 6.65.0)

Code Analysis

Commit: 3f8594e

Fixed favicon lookup usage of external request (#30918)

Mitigation Strategies

  • Upgrade Ghost to version 6.65.0 or later to apply the official security patch.
  • Enforce outbound firewall boundaries at the operating system or cloud configuration layer.
  • Proxy outbound application traffic through a dedicated forward proxy with restricted destination ACLs.

Remediation Steps:

  1. Step 1: Inspect the running Ghost application version via the admin panel or package manifest.
  2. Step 2: Execute command 'npm install ghost@6.65.0' or use the CLI updater 'ghost update' to upgrade the instance.
  3. Step 3: Establish local host egress rules limiting outbound TCP requests to valid public subnets.

References


Read the full report for CVE-2026-105647 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)