What is CVE-2026-25552?
Ghost CLI versions before 1.30.1 contain an IP spoofing vulnerability allowing unauthenticated remote attackers to bypass rate-limiting. Attackers can manipulate the X-Forwarded-For header chain via a misconfigured Nginx configuration. Users should fix Nginx setups and update Ghost CLI to the latest version.
Azərbaycanca: Ghost CLI-nin 1.30.1-dən əvvəlki versiyalarında IP spoofing zəifliyi aşkarlanıb. Təhqiqatsız uzaq hücumçu səhv konfiqurasiyalı Nginx vasitəsilə X-Forwarded-For başlığını manipulyasiya edərək rate-limiting müdafiələrindən yan keçə bilər. Ghost istifadəçiləri Nginx konfiqurasiyalarını düzəltməli və Ghost CLI-ni ən son versiyaya yeniləməlidir.
FAQ2
What versions are affected by the CVE-2026-25552 vulnerability in Ghost CLI and what can an attacker achieve?
The vulnerability affects Ghost CLI versions before 1.30.1. An unauthenticated remote attacker can bypass rate-limiting defenses by manipulating the X-Forwarded-For header via a misconfigured Nginx configuration.
What measures should Ghost users take to protect against the CVE-2026-25552 vulnerability?
Ghost users should fix their Nginx configurations and update Ghost CLI to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.