PT-2026-29855 · Postiz · Postiz
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Postiz versions prior to 2.21.4
Description
An issue exists in the creation of webhooks where the
POST /webhooks/ endpoint fails to properly validate the url field. While it performs a format check, it lacks a validator to block internal or private network addresses. Consequently, when a post is published, the orchestrator retrieves the stored URL without runtime validation, allowing for blind Server-Side Request Forgery (SSRF)—a technique where an attacker forces a server to make requests to an internal resource—against internal services.Recommendations
Update to version 2.21.4.
Avoid using the
url parameter in the POST /webhooks/ endpoint to point to internal network addresses until the update is applied.Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Postiz