CVE 6.1 MEDIUM

Ghost 6.0.6 – SSRF via oEmbed Bookmark_CVE-2025-9862

6.1 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N

Description

Server-Side Request Forgery (SSRF) vulnerability in Ghost allows an attacker to access internal resources.This issue affects Ghost: from 6.0.0 through 6.0.8, from 5.99.0 through 5.130.3.

Basic Information

ID CVE-2025-9862
Source Fluid Attacks
Published Sep 17, 2025 at 15:02

Affected Product

Vendor Ghost
Product Ghost
Version 6.0.0
Affected Versions Ghost Ghost 6.0.0
Ghost Ghost 5.99.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.