Skip to content
PSA-2026-04-1YDYCVE-2026-42298GCVE-125-2026-04-1YDYApril 24, 2026
9.3 Critical

Arbitrary Code Execution and Token Exfiltration in pr-docker-build.yml via untrusted Dockerfile.dev

Affected (1)

  • gitroomhqpostiz-app
    • ≥ 0Fixed in 0Affected

    All other versions: Unaffected

Mitigations

Exploits

  • Full read-write access to the entire postiz-app repo.

Overview

A critical "Pwn Request" vulnerability in the Build and Publish PR Docker Image workflow (.github/workflows/pr-docker-build.yml) allows any unauthenticated user to execute arbitrary code during the Docker build process and exfiltrate a highly privileged GITHUB_TOKEN (write-all permissions). This can be achieved simply by opening a Pull Request from a fork with a maliciously modified Dockerfile.dev.

Severity

CVSS v4
9.3 Critical
9.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Vuln Confidentiality
High
Vuln Integrity
High
Vuln Availability
High
Sub Confidentiality
High
Sub Integrity
High
Sub Availability
High
CVSS v3
10.0 Critical
10.0
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Weaknesses (1)

References (2)

Credits (3)

  • smiotani-aeyesec
    Reporter · @smiotani-aeyesec
  • Enno Gelhaus
    Remediation developer · @egelhaus
  • Enno Gelhaus
    Coordinator · @egelhaus

Context

Impacts

  • Attacker gains ability to commit to the repo.

  • Attacker gains ability to create releases on the repo.

  • Attacker can close, open, manage PRs / Issues.

  • Attacker gains full read-write access to all areas of the repo.

Timeline

  1. 04/22/2026 06:31

    Postiz has received the advisory.

  2. 04/22/2026 08:58

    Postiz has acknowledged the advisory.

  3. 04/22/2026 14:22

    Postiz has developed the fix, tested it and published the advisory.

  4. 04/26/2026 13:09

    GitHub has issued CVE-2026-42298 for this Advisory.

© 2026 Gelhaus Solutions