CyberRota Analysis
AI-GeneratedGhost, a Node.js content management system, has a validation issue that affects versions 6.26.0 to 6.54.1, allowing unauthenticated users to exploit certain functionalities, like Webmentions, to make limited HTTP requests to internal network hosts. While the attack does not yield response data, it poses a risk of internal network probing. Organizations using affected versions should prioritize updating to 6.54.1 to mitigate potential exposure.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Ghost is a Node.js content management system. From 6.26.0 until 6.54.1, a validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP requests to hosts in the Ghost server's internal network. A successful attack would not result in any response data being returned. This vulnerability is fixed in 6.54.1.