THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-gcvv-72q8-9v76 (medium) — Ghost: Server-Side Request Forgery in Image Fetching

[GHSA] GHSA-gcvv-72q8-9v76 (medium) — Ghost: Server-Side Request Forgery in Image Fetching

highgithub_advisoriesPublished 2026-08-04

GHSA-gcvv-72q8-9v76 Severity: medium CVE: CVE-2026-70591

Ghost: Server-Side Request Forgery in Image Fetching

### Impact

A Server-Side Request Forgery (SSRF) in Ghost Admin allowed any staff-level user to perform a blind HTTP GET request against internal hosts. No output was returned, but this could have been used to probe open ports on internal hosts.

### Vulnerable versions

This vulnerabili

Indicators of compromise

Original source: https://github.com/advisories/GHSA-gcvv-72q8-9v76