Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-29242 | Ghost vulnerable to Server Side Request Forgery (SSRF) via oEmbed Bookmark |
Github GHSA |
GHSA-f7qg-xj45-w956 | Ghost vulnerable to Server Side Request Forgery (SSRF) via oEmbed Bookmark |
Thu, 29 Jan 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:ghost:ghost:*:*:*:*:*:node.js:*:* | |
| Metrics |
cvssV3_1
|
Thu, 18 Sep 2025 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ghost
Ghost ghost |
|
| Vendors & Products |
Ghost
Ghost ghost |
Wed, 17 Sep 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 17 Sep 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Server-Side Request Forgery (SSRF) vulnerability in Ghost allows an attacker to access internal resources.This issue affects Ghost: from 6.0.0 through 6.0.8, from 5.99.0 through 5.130.3. | |
| Title | Ghost 6.0.6 - SSRF via oEmbed Bookmark | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2025-09-17T15:42:32.020Z
Reserved: 2025-09-02T17:46:31.153Z
Link: CVE-2025-9862
Updated: 2025-09-17T15:42:22.261Z
Status : Analyzed
Published: 2025-09-17T15:15:43.937
Modified: 2026-02-24T18:36:18.247
Link: CVE-2025-9862
No data.
OpenCVE Enrichment
Updated: 2025-09-18T11:59:06Z
EUVD
Github GHSA