PT-2025-29269 · Postiz · Postiz

Prdngr

·

Published

2025-07-11

·

Updated

2025-07-11

·

CVE-2025-53641

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Postiz versions 1.45.1 through 1.62.3
Description: The Postiz frontend application allows an attacker to inject arbitrary HTTP headers into the middleware pipeline. This enables a server-side request forgery (SSRF) condition, allowing unauthorized outbound requests from the server hosting the Postiz application.
Recommendations: Update to version 1.62.3 or later.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2025-53641
GHSA-48C8-25JQ-M55F

Affected Products

Postiz