
CVE-2026-70591 Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a Server-Side Request Forgery in Ghost Admin image fetching allowed any staff-level user to pe… https://www.cve.org/CVERecord?id=CVE-2026-70591
Post summary
A new CVE (CVE-2026-70591) identifies a Server‑Side Request Forgery vulnerability in Ghost CMS versions 0.10.0 to 6.54.1 that can be leveraged by staff‑level users.

