PT-2026-32029 · Postiz · Postiz

S4Nso

·

Published

2026-04-10

·

Updated

2026-04-10

·

CVE-2026-40168

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions Postiz versions prior to 2.21.5
Description Postiz, an AI social media scheduling tool, has a Server-Side Request Forgery (SSRF) issue in the /api/public/stream endpoint. The application validates the initial URL but does not re-validate the final destination after HTTP redirects. This allows an attacker to provide a public HTTPS URL that passes initial validation and then redirects the server-side request to an internal resource.
Recommendations Update to version 2.21.5 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40168

Affected Products

Postiz