CVE-2026-42298

Postiz is an AI social media scheduling tool. Prior to commit da44801, a "Pwn Request" vulnerability in the Build and Publish PR Docker Image workflow (.github/workflows/pr-docker-build.yml) allows any unauthenticated user to execute arbitrary code during the Docker build process and exfiltrate a highly privileged GITHUB_TOKEN (write-all permissions). This can be achieved simply by opening a Pull Request from a fork with a maliciously modified Dockerfile.dev. This issue has been patched via commit da44801.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gitroom:postiz:*:*:*:*:*:*:*:*

History

24 Jul 2026, 21:10

Type Values Removed Values Added
Summary
  • (es) Postiz es una herramienta de programación de redes sociales con IA. Antes del commit da44801, una vulnerabilidad 'Pwn Request' en el flujo de trabajo de compilación y publicación de imágenes Docker de PR (.github/workflows/pr-docker-build.yml) permite a cualquier usuario no autenticado ejecutar código arbitrario durante el proceso de compilación de Docker y exfiltrar un GITHUB_TOKEN altamente privilegiado (permisos de escritura total). Esto se puede lograr simplemente abriendo una solicitud de extracción desde un fork con un Dockerfile.dev modificado maliciosamente. Este problema ha sido parcheado mediante el commit da44801.

01 Jun 2026, 16:42

Type Values Removed Values Added
CPE cpe:2.3:a:gitroom:postiz:*:*:*:*:*:*:*:*
First Time Gitroom
Gitroom postiz
References () https://github.com/gitroomhq/postiz-app/commit/da448012dd87e94944cbe83a38e7fd023269ec46 - () https://github.com/gitroomhq/postiz-app/commit/da448012dd87e94944cbe83a38e7fd023269ec46 - URL Repurposed
References () https://github.com/gitroomhq/postiz-app/security/advisories/GHSA-v975-9h5p-xhm4 - () https://github.com/gitroomhq/postiz-app/security/advisories/GHSA-v975-9h5p-xhm4 - Vendor Advisory

08 May 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-08 23:16

Updated : 2026-07-24 21:10


NVD link : CVE-2026-42298

Mitre link : CVE-2026-42298

CVE.ORG link : CVE-2026-42298


JSON object : View

Products Affected

gitroom

  • postiz
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')