CVE-2026-40487Disclosure(gitroom / postiz)

HIGHCVSS 9.0 · CRITICAL

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch gitroom postiz systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file upload validation bypass allows any authenticated user to upload arbitrary HTML, SVG, or other executable file types to the server by spoofing the `Content-Type` header. The uploaded files are then served by nginx with a Content-Type derived from their original extension (`text/html`, `image/svg+xml`), enabling Stored Cross-Site Scripting (XSS) in the context of the application's origin. This can lead to session riding, account takeover, and full compromise of other users' accounts. Version 2.21.6 contains a fix.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-345CWE-434

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • postiz

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 8 mentions across 4 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 8 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-04-18); latest day: 1
  • 8 total mentions across 4 days

Affected systems

Vendors
Products
postiz

Deep dive

Activity timeline8 mentions / 4d
01223Mentions · 2026-04-16: 2Mentions · 2026-04-17: 2Mentions · 2026-04-18: 3Mentions · 2026-04-20: 1PoC Mentioned / Linked · 2026-04-16: 1PoC Mentioned / Linked · 2026-04-17: 1Exploit Tool / Code · 2026-04-16: 1Active Exploitation · 2026-04-18: 1Patch / Workaround · 2026-04-17: 1Patch / Workaround · 2026-04-18: 1Technical Details · 2026-04-16: 2Technical Details · 2026-04-17: 2Technical Details · 2026-04-18: 3Technical Details · 2026-04-20: 104-1604-1704-1804-20
Signal classification4 categories
Disclosure
337.5%
General
225.0%
PoC
225.0%
Active Exploitation
112.5%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-162
General1PoC1
2026-04-172
General1PoC1
2026-04-183
Active Exploitation1Disclosure2
2026-04-201
Disclosure1
Full discourse8 posts
  • Dark Web Informer@DarkWebInformer
    PoC

    ‼️ CVE-2026-40487: Postiz <= 2.21.5 - Arbitrary File Upload via MIME-Type Spoofing to Stored XSS to Account Takeover PoC CVSS: 8.9 PoC on GitHub: https://github.com/Astaruf/CVE-2026-40487 Postiz is an open-source social media management tool with 28+ platform integrations (Instagram, X, LinkedIn, Facebook, TikTok, etc.), used by 600+ instances exposed on the internet.

    Post summary

    The post announces CVE-2026-40487 for Postiz, provides a PoC on GitHub, details the exploit pathway, and indicates the severity with a CVSS score of 8.9.

    17032176.9K
    221.5K followersView on X
  • FOFA@fofabot
    Disclosure

    ⚠️⚠️ CVE-2026-40487: Postiz file-upload validation bypass may allow execution of uploaded active content. 🔗FOFA Link: https://en.fofa.info/result?qbase64=aWNvbl9oYXNoPSI3MjQ5ODU1MTEi 🎯6.5K+ Results are found on http://en.fofa.info. FOFA Query: icon_hash="724985511" 🔖Refer: https://nvd.nist.gov/vuln/detail/CVE-2026-40487 #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    The post announces CVE‑2026‑40487, a Postiz file‑upload validation bypass that may allow execution of active content, and highlights FOFA search results for further investigation.

    010721.6K
    14.4K followersView on X
  • z3n@zench4n
    PoC

    File upload vulnerabilities are resurfacing. Check out Astaruf/CVE-2026-40487 on GitHub, detailing arbitrary file upload via MIME-type spoofing in Postiz. If your AI agent can ingest or upload files, validate every byte. Trusting metadata is a recipe for disaster.

    Post summary

    The text highlights a GitHub PoC for CVE-2026-40487 that demonstrates arbitrary file uploads via MIME spoofing, while recommending byte-level validation as a mitigation.

    100109
    1.5K followersView on X
  • NerdieNews@NewsNerdie
    Active Exploitation

    Postiz CVE-2026-40487 is under active exploitation—attackers can upload spoofed files leading to stored XSS. This vulnerability puts systems at risk of full compromise. Patch now to prevent exploitation. #NerdieNews #CyberSecurity #InfoSec #Vulnerability https://t.co/JsfumJKqRl

    Post summary

    CVE‑2026‑40487 is being actively exploited; attackers upload spoofed files that trigger stored XSS, potentially leading to full system compromise. Immediate patching is recommended.

    0001069
    55 followersView on X
  • z3n@zench4n
    General

    Keep an eye on the supply chain. Check the Astaruf/CVE-2026-40487 repo for insights on MIME-type spoofing leading to arbitrary file uploads. If your AI agent processes user-uploaded files, validate everything. Stay sharp.

    Post summary

    A repository is cited for insights into the CVE-2026-40487 vulnerability, which involves MIME‑type spoofing allowing arbitrary file uploads, but no exploit code, patch, or active exploitation details are provided.

    000108
    1.5K followersView on X
  • z3n@zench4n
    General

    The risk scales with autonomy. An agent reading an untrusted email or webpage can be manipulated into executing unauthorized actions. If an agent has access to a system with unpatched flaws like CVE-2026-40487, a single malicious payload can lead to arbitrary file uploads.

    Post summary

    Mentions CVE-2026-40487, noting that an unpatched system could enable arbitrary file uploads via a malicious payload presented to an autonomous agent.

    1000030
    1.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40487 Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file upload validation bypass allows any authenticated user to upload arbitrary HTML, SVG, or… https://www.cve.org/CVERecord?id=CVE-2026-40487

    Post summary

    The CVE reveals a file‑upload validation bypass in Postiz up to v2.21.6 that permits authenticated users to upload arbitrary HTML or SVG files, potentially enabling content‑based attacks.

    0000092
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40487 File Upload Validation Bypass Leading to Stored XSS in Postiz Before 2.21.6 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40487

    Post summary

    The entry announces CVE-2026-40487: a file upload validation bypass in Postiz that allows stored XSS; no PoC, exploit, patch, or active exploitation is reported.

    0000059
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgitroompostiz---

Explore more