THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-g366-23fw-ggp6 (medium) — Ghost: Mobiledoc image-size fetch SSRF

[GHSA] GHSA-g366-23fw-ggp6 (medium) — Ghost: Mobiledoc image-size fetch SSRF

highgithub_advisoriesPublished 2026-08-04

GHSA-g366-23fw-ggp6 Severity: medium CVE: CVE-2026-53946

Ghost: Mobiledoc image-size fetch SSRF

### Impact

When re-rendering posts, Ghost would refetch missing image dimensions by issuing an outbound HTTP request to the URL stored on an image card — without restricting that URL to trusted image hosts. An authenticated staff user able to create or edit posts could therefore point an image card a

Indicators of compromise

Original source: https://github.com/advisories/GHSA-g366-23fw-ggp6