« Volver al listado

CVE-2025-9862

Estado: AnalizadaMedia (6.1)—

Server-Side Request Forgery (SSRF) vulnerability in Ghost allows an attacker to access internal resources.This issue affects Ghost: from 6.0.0 through 6.0.8, from 5.99.0 through 5.130.3.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-9862",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-9862",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-09-17T15:42:29.239311Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "help@fluidattacks.com",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 6.1,
          "Automatable": "NOT_DEFINED",
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "NONE",
          "privilegesRequired": "HIGH",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "NONE",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "NONE",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "HIGH",
          "vulnConfidentialityImpact": "NONE",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "help@fluidattacks.com",
      "affectedData": [
        {
          "vendor": "Ghost",
          "product": "Ghost",
          "versions": [
            {
              "status": "affected",
              "version": "6.0.0",
              "versionType": "custom",
              "lessThanOrEqual": "6.0.8"
            },
            {
              "status": "affected",
              "version": "5.99.0",
              "versionType": "custom",
              "lessThanOrEqual": "5.130.3"
            }
          ],
          "platforms": [
            "Linux"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-09-17T15:15:43.937",
  "references": [
    {
      "url": "https://fluidattacks.com/advisories/regida",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "help@fluidattacks.com"
    },
    {
      "url": "https://github.com/TryGhost/Ghost",
      "tags": [
        "Product"
      ],
      "source": "help@fluidattacks.com"
    },
    {
      "url": "https://github.com/TryGhost/Ghost/releases/tag/v6.0.9",
      "tags": [
        "Patch"
      ],
      "source": "help@fluidattacks.com"
    },
    {
      "url": "https://github.com/TryGhost/Ghost/security/advisories/GHSA-f7qg-xj45-w956",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "help@fluidattacks.com"
    },
    {
      "url": "https://fluidattacks.com/advisories/regida",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "help@fluidattacks.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-918"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Server-Side Request Forgery (SSRF) vulnerability in Ghost allows an attacker to access internal resources.This issue affects Ghost: from 6.0.0 through 6.0.8, from 5.99.0 through 5.130.3."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de falsificación de petición del lado del servidor (SSRF) en Ghost permite a un atacante acceder a recursos internos. Este problema afecta a Ghost: desde la versión 6.0.0 hasta la 6.0.8, y desde la 5.99.0 hasta la 5.130.3."
    }
  ],
  "lastModified": "2026-06-17T10:09:55.353",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ghost:ghost:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "98A3D8EC-304F-4B68-BA55-556364BD4779",
              "versionEndIncluding": "5.130.3",
              "versionStartIncluding": "5.99.0"
            },
            {
              "criteria": "cpe:2.3:a:ghost:ghost:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2A9FDF80-22BA-4F3F-85C5-B07675649142",
              "versionEndIncluding": "6.0.8",
              "versionStartIncluding": "6.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "help@fluidattacks.com"
}