CVE-2026-105647: Server-Side Request Forgery via Favicon Probing in Ghost CMS
Vulnerability ID: CVE-2026-105647
CVSS Score: 4.0
Published: 2026-10-07
An unauthenticated Server-Side Request Forgery (SSRF) vulnerability exists in Ghost CMS from version 6.54.1 to 6.65.0. The vulnerability stems from a validation bypass in the favicon resolution logic within the bookmark-fetching subsystem, which allows remote, unauthenticated attackers to trigger arbitrary HTTP requests to the local host and internal networks. This bypass circumvents the custom DNS-level IP blocklist controls configured globally in the application.
TL;DR
Ghost CMS versions 6.54.1 through 6.64.0 are vulnerable to unauthenticated blind SSRF due to a validation bypass in the favicon resolution flow. Attackers can leverage this to make HTTP requests targeting private and loopback networks.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-918 / CWE-367
- Attack Vector: Network
- CVSS v3.1 Score: 4.0 (Medium)
- Exploit Status: PoC / Analytical
- CISA KEV Status: Not Listed
- Impact: Low Confidentiality (Blind SSRF)
Affected Systems
- Ghost Content Management System (CMS)
-
Ghost: >= 6.54.1, < 6.65.0 (Fixed in:
6.65.0)
Code Analysis
Commit: 3f8594e
Fixed favicon lookup usage of external request (#30918)
Mitigation Strategies
- Upgrade Ghost to version 6.65.0 or later to apply the official security patch.
- Enforce outbound firewall boundaries at the operating system or cloud configuration layer.
- Proxy outbound application traffic through a dedicated forward proxy with restricted destination ACLs.
Remediation Steps:
- Step 1: Inspect the running Ghost application version via the admin panel or package manifest.
- Step 2: Execute command 'npm install ghost@6.65.0' or use the CLI updater 'ghost update' to upgrade the instance.
- Step 3: Establish local host egress rules limiting outbound TCP requests to valid public subnets.
References
Read the full report for CVE-2026-105647 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)