CVE-2026-34590

Postiz is an AI social media scheduling tool. Prior to version 2.21.4, the POST /webhooks/ endpoint for creating webhooks uses WebhooksDto which validates the url field with only @IsUrl() (format check), missing the @IsSafeWebhookUrl validator that blocks internal/private network addresses. The update (PUT /webhooks/) and test (POST /webhooks/send) endpoints correctly apply @IsSafeWebhookUrl. When a post is published, the orchestrator fetches the stored webhook URL without runtime validation, enabling blind SSRF against internal services. This issue has been patched in version 2.21.4.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gitroom:postiz:*:*:*:*:*:*:*:*

History

24 Jul 2026, 21:10

Type Values Removed Values Added
Summary
  • (es) Postiz es una herramienta de programación de redes sociales con IA. Antes de la versión 2.21.4, el endpoint POST /webhooks/ para crear webhooks utiliza WebhooksDto, que valida el campo 'url' solo con @IsUrl() (verificación de formato), faltando el validador @IsSafeWebhookUrl que bloquea direcciones de red internas/privadas. Los endpoints de actualización (PUT /webhooks/) y prueba (POST /webhooks/send) aplican correctamente @IsSafeWebhookUrl. Cuando se publica una publicación, el orquestador recupera la URL del webhook almacenada sin validación en tiempo de ejecución, lo que permite SSRF ciego contra servicios internos. Este problema ha sido parcheado en la versión 2.21.4.

07 Apr 2026, 21:21

Type Values Removed Values Added
CPE cpe:2.3:a:gitroom:postiz:*:*:*:*:*:*:*:*
References () https://github.com/gitroomhq/postiz-app/commit/5ae4c950db6aa516a31454b7a45b9480bca40a11 - () https://github.com/gitroomhq/postiz-app/commit/5ae4c950db6aa516a31454b7a45b9480bca40a11 - Patch
References () https://github.com/gitroomhq/postiz-app/releases/tag/v2.21.4 - () https://github.com/gitroomhq/postiz-app/releases/tag/v2.21.4 - Product, Release Notes
References () https://github.com/gitroomhq/postiz-app/security/advisories/GHSA-wc9c-7cv8-m225 - () https://github.com/gitroomhq/postiz-app/security/advisories/GHSA-wc9c-7cv8-m225 - Exploit, Mitigation, Vendor Advisory
First Time Gitroom
Gitroom postiz

02 Apr 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-02 18:16

Updated : 2026-07-24 21:10


NVD link : CVE-2026-34590

Mitre link : CVE-2026-34590

CVE.ORG link : CVE-2026-34590


JSON object : View

Products Affected

gitroom

  • postiz
CWE
CWE-918

Server-Side Request Forgery (SSRF)