CVE-2026-105648mediumCWE-184CWE-918

CVE-2026-105648: fallo de gravedad media en TryGhost Ghost

Ghost: Private IP Filtering Bypass via IPv6 Transition Addresses

Publicada el · Actualizada el

13Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 4epss 0.3%
probabilidad de explotación
0.3%top 79% de las CVE
explotación observada
noninguna fuente lo reporta
Ghost is a Node.js content management system. From 6.0.9 until 6.65.0, a validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP requests to hosts in the Ghost server's internal network on some network configurations. A successful attack would not result in any response data being returned. This issue is fixed in version 6.65.0.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
Productos afectados
TryGhost · Ghost