Published advisories
Advisories published by GAdvisory.
PSA-2026-4QX1WGCVE-2026-107761October 11, 2026Postiz AppChannel tokens and organization API key exposed in API responses
Two authenticated Postiz endpoints returned the full database row instead of the fields the client needs. Deleting a channel through the public API returned that channel's platform access and refresh tokens to the calling OAuth app, and GET /user/organizations returned the organization API key to every member, although it is meant to be visible to admins only.
MediumPSA-2026-P8W1J0CVE-2026-94455September 22, 2026Postiz AppUnauthenticated /enterprise/create-user mints lifetime top-tier organizations and discloses their API key
The /enterprise/create-user endpoint is not covered by authentication middleware and accepts any token signed with the instance JWT secret. Ordinary login tokens are signed with that same secret and carry no purpose claim, so any registered user can replay their own session token to create a new organisation with a permanent top-tier subscription and receive its API key in the response. Only deployments with billing enabled are affected.
HighPSA-2026-TD98KYCVE-2026-94456September 22, 2026Postiz AppUnauthenticated recovery of the Math.random() state behind OAuth tokens, authorization codes, client secrets and organization API keys
Postiz generates OAuth access tokens, authorization codes, OAuth client secrets and per-organization API keys with a helper that draws every character from Math.random(), a non-cryptographic generator. Its output is directly observable, in bulk, from an endpoint that requires no authentication. Recovering the generator's internal state from that output is a linear-algebra problem, after which credentials minted for other organizations follow deterministically.
CriticalGSSA-2026-09-HREC4XGHSA-7mh4-g74q-c7q8September 14, 2026GPlatform ControlCloud broker issues and replaces application credentials without authentication
The application registration endpoint on the cloud broker verified no credential before issuing one. A caller naming an existing application instance received a valid credential for it, and the stored credential was replaced. Rotation did not remediate the issue.
CriticalGSSA-2026-09-CDC8AGGHSA-8r5c-7cc5-j3v6September 14, 2026GPlatform ControlFailed second-factor codes are not counted toward account lockout
A failed password attempt counted toward an account lockout; a failed one-time code did not, on either sign in or re-authentication, and no rate limiting applied. An attacker holding a valid password could guess the second factor without limit.
HighGSSA-2026-09-KNEEEVGHSA-vwpc-mpmp-q983September 14, 2026GPlatform ControlPrivileged administrative operations did not declare required roles
Role requirements were declared per operation and most privileged operations declared none, which admitted any role. The lowest-privilege role, assigned by default when an account is created without one, could change customer licensing and publish signed software.
HighPSA-2026-G1CT26GCVE-125-2026-G1CT26August 15, 2026Postiz CloudDMARC not enabled for postiz.com
Postiz has not enabled DMARC on their primary domain, resulting to email forgery.
MediumPSA-2026-TH12B7CVE-2026-19264August 7, 2026Postiz AppUnauthenticated arbitrary file read via /uploads path traversal (URL-encoded separators) leading to instance takeover
Unauthenticated arbitrary file read via /uploads path traversal (URL-encoded separators) leading to instance takeover
CriticalPSA-2026-NWZN9JCVE-2026-19127June 22, 2026Postiz AppInsufficient verification of lifetime-deal redemption codes allows forgery of permanent paid subscriptions
MediumPSA-2026-Q3TCPKCVE-2026-48799May 23, 2026Postiz AppUnauthenticated arbitrary lifetime PRO grant via Nowpayments webhook
MediumPSA-2026-WWFR8XCVE-2026-48783May 22, 2026Postiz AppUnauthenticated billing-enforcement bypass via /public/modify-subscription
MediumPSA-2026-2CAQ96CVE-2026-48781May 22, 2026Postiz AppSUPERADMIN takeover via Skool-provider JWT forgery
Attackers can exploit the skool-provider JWT sign process to generate a JWT token with isSuperAdmin: true
HighGSSA-2026-05-442ENFGITLAB-GSSA-2026-05-442ENFMay 7, 2026Contribution CheckerCRLF injection in email subject via project name
Project name was interpolated into outbound email subjects without rejecting CR/LF, so an admin could inject extra headers (Bcc, etc.) via the project settings form. Fixed by rejecting line breaks in the project name validator.
LowGSSA-2026-05-P6SB4WGITLAB-GSSA-2026-05-P6SB4WMay 7, 2026Contribution CheckerMissing browser security response headers
The dashboard shipped without CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, or HSTS, leaving it exposed to clickjacking, MIME-sniffing, and missing the standard defense-in-depth layer against same-origin XSS. Fixed by adding the standard security header set in next.config.ts.
MediumGSSA-2026-05-J0ZPKKGITLAB-GSSA-2026-05-J0ZPKKMay 6, 2026Contribution CheckerUnbounded request body on webhook and CI endpoints
The GitHub webhook and CI check-pr API routes read the full request body before any validation. Anyone able to reach the endpoints could post a multi-GB body and exhaust process memory. Fixed by adding a streaming size cap (1MB and 2MB respectively) that returns 413 before signature or JWT verification.
HighGSSA-2026-05-A5DE8WGITLAB-GSSA-2026-05-A5DE8WMay 4, 2026Contribution CheckerSSRF in outbound project webhook delivery
A project admin could register an outbound webhook URL that resolved to internal addresses (cloud metadata, loopback, RFC1918), and the response body was persisted and exposed in the project settings UI. Fixed by validating URLs against a private-address blocklist before each delivery.
MediumGSSA-2026-05-JHA9SZGITLAB-GSSA-2026-05-JHA9SZMay 4, 2026Contribution CheckerBearer tokens and webhook signatures could leak to Sentry
Sentry capture ran without a beforeSend filter, so caught errors carrying request metadata (Authorization headers, x-hub-signature-256, GitHub installation tokens, JWT bodies) could be serialized into Sentry events. Fixed by adding a recursive scrubber on both server and edge runtimes.
MediumPSA-2026-04-M1S0CVE-2026-42346April 28, 2026Postiz AppTOCTOU DNS rebinding bypasses all SSRF URL validation paths
TOCTOU DNS rebinding bypasses all SSRF URL validation paths
MediumPSA-2026-T0E4W0CVE-2026-42556April 27, 2026Postiz AppPostiz stored XSS in public preview page
Postiz stored XSS in public preview page
HighGSSA-2026-04-AMHCRRGITLAB-GSSA-2026-04-AMHCRRApril 25, 2026CoBC Event TrackerWeak default fallback secrets allow JWT and CSRF token forgery in cobc-events
cobc-events <1.0.1 fell back to hard-coded development secrets when JWT_SECRET / SESSION_SECRET were unset, allowing forgery of session JWTs and CSRF HMAC tokens.
CriticalGSSA-2026-04-P1V3KVGITLAB-GSSA-2026-04-P1V3KVApril 25, 2026CoBC Event TrackerNon-constant-time CSRF token comparison and lax hex parsing in cobc-events
The CSRF middleware in cobc-events <1.0.1 compared the cookie nonce with `!==` before the timing-safe HMAC check and accepted malformed hex input, leaking timing data and weakening token verification.
MediumGSSA-2026-04-RSDKJ2GITLAB-GSSA-2026-04-RSDKJ2April 25, 2026CoBC Event TrackerPermissive CORS configuration allows credentialed cross-origin requests in cobc-events
cobc-events <1.0.1 enabled CORS with the default `cors()` configuration, accepting any `Origin`. Combined with the JWT cookie, this allowed cross-origin sites to issue authenticated requests against the API.
MediumGSSA-2026-04-4YYSARGITLAB-GSSA-2026-04-4YYSARApril 25, 2026CoBC Event TrackerMissing HSTS and incomplete CSP directives in cobc-events
cobc-events <1.0.1 did not set Strict-Transport-Security and was missing key Content-Security-Policy directives (`frame-ancestors`, `object-src`, `base-uri`, `form-action`), enabling downgrade and clickjacking attacks.
MediumGSSA-2026-04-PR3QFFGITLAB-GSSA-2026-04-PR3QFFApril 25, 2026CoBC Event TrackerIDOR on /api/loa/user/:userId and /api/strikes/user/:userId in cobc-events
Endpoints returning another user's LoA/strikes only required `view_own_*` permission and did not enforce that the caller owned the path parameter, allowing any authenticated host to read other users' history.
MediumGSSA-2026-04-XJKMV4GITLAB-GSSA-2026-04-XJKMV4April 25, 2026CoBC Event TrackerPermissive file upload filter accepts SVG enabling stored XSS in cobc-events
The multer fileFilter in cobc-events <1.0.1 used the regex `^(image|video|application/pdf)`, which matches `image/svg+xml` and any `video/*` MIME type. SVG uploads enable stored XSS when later served from the application origin.
MediumGSSA-2026-04-RHBD5TGITLAB-GSSA-2026-04-RHBD5TApril 25, 2026CoBC Event TrackerDiscord bot /config and /setchannel commands lacked authorization in cobc-events
The `/config` and `/setchannel` slash commands in cobc-events <1.0.1 had no permission check, letting any guild member toggle logging features or reroute strike/event/LoA log channels.
HighGSSA-2026-04-3ZVC5DGITLAB-GSSA-2026-04-3ZVC5DApril 25, 2026CoBC Event TrackerUnbounded pagination limits enable resource exhaustion in cobc-events
Several REST endpoints accepted a client-controlled `limit` query parameter with no upper bound, allowing authenticated users to request arbitrarily large result sets and exhaust database / memory.
MediumGSSA-2026-04-8PDG13GITLAB-GSSA-2026-04-8PDG13April 25, 2026CoBC Event TrackerStrike status filter accepted arbitrary strings in cobc-events
`/api/strikes` previously accepted any comma-separated string in `?status=` and forwarded it to the service layer without validation against the StrikeStatus enum.
MediumGSSA-2026-04-QH1CCPGITLAB-GSSA-2026-04-QH1CCPApril 25, 2026CoBC Event TrackerCache invalidation used blocking Redis KEYS command in cobc-events
`CacheService.invalidatePattern` called `redis.keys(pattern)`, which blocks the Redis instance. On large keyspaces this could stall the entire Redis server and create a denial-of-service condition.
MediumGSSA-2026-04-TPJNF1GITLAB-GSSA-2026-04-TPJNF1April 25, 2026CoBC Event TrackerStored XSS via manual HTML escaping in events log-outcome view in cobc-events
The `log-outcome.ejs` template used the unescaped `<%-` output tag with hand-rolled HTML escaping that did not cover all XSS vectors, allowing stored XSS via `event.notes`.
MediumPSA-2026-04-1YDYCVE-2026-42298April 24, 2026Postiz AppArbitrary Code Execution and Token Exfiltration in pr-docker-build.yml via untrusted Dockerfile.dev
CriticalPSA-2026-04-6EZ5CVE-2026-40168April 22, 2026Postiz AppServer-Side Request Forgery via Redirect Bypass in /api/public/stream
Server-Side Request Forgery via Redirect Bypass in /api/public/stream
HighPSA-2026-04-5MVGCVE-2026-40487April 19, 2026Postiz AppUnrestricted File Upload via MIME Type Spoofing Leads to Stored XSS
Unrestricted File Upload via MIME Type Spoofing Leads to Stored XSS
CriticalPSA-2026-04-HVBMCVE-2026-34590April 19, 2026Postiz AppSSRF via Webhook Creation Endpoint Missing URL Safety Validation
SSRF via Webhook Creation Endpoint Missing URL Safety Validation
MediumPSA-2026-04-KT4WCVE-2026-34576April 19, 2026Postiz AppSSRF in upload-from-url endpoint allows fetching internal resources and cloud metadata
SSRF in upload-from-url endpoint allows fetching internal resources and cloud metadata
MediumPSA-2026-04-422GCVE-2026-34577April 19, 2026Postiz AppUnauthenticated Full-Read SSRF via /public/stream Endpoint with Trivially Bypassable Extension Check
Unauthenticated Full-Read SSRF via /public/stream Endpoint with Trivially Bypassable Extension Check
HighPSA-2026-04-SRGACVE-2024-34351April 19, 2026Postiz AppHigh-Severity SSRF in Postiz App
High-Severity SSRF in Postiz App
HighPSA-2026-04-ZR1MGHSA-89v5-38xr-9m4jApril 19, 2026Postiz AppMultiple SSRF Vectors - Webhooks, RSS Feed, URL Loader (CWE-918)
Multiple SSRF Vectors - Webhooks, RSS Feed, URL Loader (CWE-918)
HighPSA-2026-04-PY6VCVE-2025-53641April 19, 2026Postiz AppHeader mutation in middleware facilitates SSRF
Header mutation in middleware facilitates SSRF
High