CVE-2026-22597
Last modified
CVE-2026-22597 is a low-severity vulnerability rated 2.7/10 on the CVSS scale. Ghost is a Node.js content management system. In versions 5.38.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost’s media inliner mechanism allows staff users in possession of a valid authentication token for the Ghost Admin API to exfiltrate data from internal systems via SSRF. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
Ghost is a Node.js content management system. In versions 5.38.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost’s media inliner mechanism allows staff users in possession of a valid authentication token for the Ghost Admin API to exfiltrate data from internal systems via SSRF. This issue has been patched in versions 5.130.6 and 6.11.0.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ghost | Ghost | >= 5.38.0, < 5.130.6 |
| Ghost | Ghost | >= 6.0.0, < 6.11.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-22597?
How severe is CVE-2026-22597?
How do I fix CVE-2026-22597?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-22591eprosima Fast DDS is a C++ implementation of the DDS (Data D…7.5
- CVE-2026-22592Gogs is an open source self-hosted Git service. In version 0…6.5
- CVE-2026-22593EVerest is an EV charging software stack. Prior to version 2…7.8
- CVE-2026-22594Ghost is a Node.js content management system. In versions 5.…8.1
- CVE-2026-22595Ghost is a Node.js content management system. In versions 5.…8.1
- CVE-2026-22596Ghost is a Node.js content management system. In versions 5.…7.2
- CVE-2026-22598ManageIQ is an open-source management platform. A flaw was f…7.1
- CVE-2026-22599Strapi is an open source headless content management system.…7.2
- CVE-2026-2260A vulnerability was found in D-Link DCS-931L up to 1.13.0. T…7.3
- CVE-2026-22600OpenProject is an open-source, web-based project management …9.1
- CVE-2026-22601OpenProject is an open-source, web-based project management …7.2
- CVE-2026-22602OpenProject is an open-source, web-based project management …3.5
Are you affected by CVE-2026-22597?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
