
🟠 CVE-2026-34577 - High Postiz is an AI social media scheduling tool. Prior to version 2.21.3, the GET /public/stream endpoint in PublicController accepts a user-supplied url query parameter and proxies the full HTT... https://www.thehackerwire.com/vulnerability/CVE-2026-34577/ https://t.co/RHCYfY7ttV
Post summary
CVE‑2026‑34577 relates to Postiz’s GET /public/stream endpoint, enabling arbitrary URL proxying before version 2.21.3, and is classified as a high‑severity disclosure with no PoC, exploit, or patch noted.


