Junglewise Threat Intelligence

CVE-2026-34576: Postiz SSRF in upload-from-url endpoint

CVE-2026-34576 · Severity: high · CVSS 7.7 · Published 2026-04-02

Technologies: Gitroom Postiz. Vendors: Gitroom.

Executive brief

Postiz, an AI-powered social media scheduling tool, contains a security flaw in its image upload feature. An authorized user can trick the system into accessing private internal servers or cloud infrastructure metadata instead of public images. This could allow an attacker to steal sensitive cloud credentials, scan internal corporate networks, or access private databases, potentially leading to a broader breach of the organization's infrastructure.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the Postiz 'upload-from-url' endpoint due to insufficient validation of user-supplied URLs. The application uses axios.get() to fetch remote content but only performs a superficial check for image file extensions (e.g., .png, .jpg), which can be bypassed by appending a query string or fragment to the target URL. An authenticated attacker can exploit this to make requests to internal network resources, such as AWS/GCP/Azure metadata services or internal databases. The application then uploads the retrieved data to its storage and provides a download URL to the attacker, facilitating full data exfiltration. The vulnerability is resolved in version 2.21.3.

Affected products

  • gitroomhq Postiz < 2.21.3

Timeline

  • 2026-03-28: disclosed: Advisory received and verified by Postiz team
  • 2026-03-29: patched: Version 2.21.3 released
  • 2026-03-30: other: CVE identifier assigned
  • 2026-04-02: advisory: Public advisory published

References

Related threats