Executive brief
Postiz is an AI-powered social media scheduling platform. A security flaw in its billing system allowed users to bypass subscription limits for their own accounts without making a payment. While an attacker could not affect other customers' data, they could gain unauthorized access to premium features like additional team members and integrations by sending specially crafted requests to an unprotected web address.
Technical details
A vulnerability exists in the /public/modify-subscription endpoint of Postiz due to insufficient verification of data authenticity (CWE-345) and missing authorization (CWE-862). The endpoint accepts a signed token and applies subscription-enforcement side effects based on the token's claims without verifying if the token was intended for that specific purpose. While the persisted subscription tier in the database remains unchanged, the application executes side effects such as enabling extra team members, enabling integrations, and resetting post-scheduling limits. This exploit requires Stripe to be configured on the instance and is limited to the attacker's own organization. The issue is fixed in version 2.21.8.
Affected products
- gitroomhq postiz-app < 2.21.8
Timeline
- 2026-05-22: disclosed: Advisory received and verified by Postiz team
- 2026-05-22: patched: Fix developed and released in version 2.21.8
- 2026-06-17: advisory: CVE-2026-48783 published