PT-2026-39212 · Postiz · Postiz

Smiotani-Aeyesec

·

Published

2026-05-08

·

Updated

2026-05-13

·

CVE-2026-42298

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Postiz versions prior to commit da44801
Description A Pwn Request issue in the Build and Publish PR Docker Image workflow located in '.github/workflows/pr-docker-build.yml' allows unauthenticated users to execute arbitrary code during the Docker build process. This occurs when a Pull Request is opened from a fork containing a maliciously modified Dockerfile.dev, which can lead to the exfiltration of a highly privileged GITHUB TOKEN with write-all permissions.
Recommendations Update to the version containing commit da44801.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-42298

Affected Products

Postiz