CVE-2026-34577Patch(gitroom / postiz)

LOWCVSS 8.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch gitroom postiz systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Postiz is an AI social media scheduling tool. Prior to version 2.21.3, the GET /public/stream endpoint in PublicController accepts a user-supplied url query parameter and proxies the full HTTP response back to the caller. The only validation is url.endsWith('mp4'), which is trivially bypassable by appending .mp4 as a query parameter value or URL fragment. The endpoint requires no authentication and has no SSRF protections, allowing an unauthenticated attacker to read responses from internal services, cloud metadata endpoints, and other network-internal resources. This issue has been patched in version 2.21.3.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • postiz

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-04-02); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
postiz

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-02: 1Mentions · 2026-04-03: 1Mentions · 2026-04-07: 1Patch / Workaround · 2026-04-02: 1Patch / Workaround · 2026-04-07: 1Technical Details · 2026-04-02: 1Technical Details · 2026-04-03: 1Technical Details · 2026-04-07: 104-0204-0304-07
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-021
Patch1
2026-04-031
Disclosure1
2026-04-071
Patch1
Full discourse3 posts
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-34577 - High Postiz is an AI social media scheduling tool. Prior to version 2.21.3, the GET /public/stream endpoint in PublicController accepts a user-supplied url query parameter and proxies the full HTT... https://www.thehackerwire.com/vulnerability/CVE-2026-34577/ https://t.co/RHCYfY7ttV

    Post summary

    CVE‑2026‑34577 relates to Postiz’s GET /public/stream endpoint, enabling arbitrary URL proxying before version 2.21.3, and is classified as a high‑severity disclosure with no PoC, exploit, or patch noted.

    0001065
    163 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-34577: HIGH] AI social media tool Postiz had a cyber security vulnerability in GET /public/stream endpoint allowing attackers to access sensitive data without authentication, which is now fixed in ...#cve,CVE-2026-34577,#cybersecurity https://cvefind.com/CVE-2026-34577

    Post summary

    CVE‑2026‑34577 allows unauthenticated access to sensitive data via Postiz’s /public/stream endpoint, and it has been patched.

    0001054
    617 followersView on X
  • Firmis Labs@FirmisLabs
    Patch

    CVE-2026-34577 · NIST 8.6/10 https://nvd.nist.gov/vuln/detail/CVE-2026-34577 ask your AI: "check if my project uses Postiz and if it's below version 2.21.3" then: "update Postiz to version 2.21.3 or later and make sure social media scheduling still works"

    Post summary

    The post references CVE‑2026‑34577 with an 8.6/10 severity score and advises updating the Postiz component to version 2.21.3 or later to mitigate the vulnerability.

    0000026
    1 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgitroompostiz---

Explore more