CVE-2026-42298Disclosure(gitroom / postiz)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch gitroom postiz systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Postiz is an AI social media scheduling tool. Prior to commit da44801, a "Pwn Request" vulnerability in the Build and Publish PR Docker Image workflow (.github/workflows/pr-docker-build.yml) allows any unauthenticated user to execute arbitrary code during the Docker build process and exfiltrate a highly privileged GITHUB_TOKEN (write-all permissions). This can be achieved simply by opening a Pull Request from a fork with a maliciously modified Dockerfile.dev. This issue has been patched via commit da44801.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • postiz

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 3 classified signals
  • Peaked 2d ago at 3 mentions (2026-05-09); latest day: 1
  • 7 total mentions across 4 days

Affected systems

Vendors
Products
postiz

Deep dive

Activity timeline7 mentions / 4d
01223Mentions · 2026-05-08: 1Mentions · 2026-05-09: 3Mentions · 2026-05-13: 2Mentions · 2026-05-19: 1Active Exploitation · 2026-05-09: 1Patch / Workaround · 2026-05-08: 1Patch / Workaround · 2026-05-09: 1Technical Details · 2026-05-08: 1Technical Details · 2026-05-09: 2Technical Details · 2026-05-13: 105-0805-0905-1305-19
Signal classification3 categories
Disclosure
342.9%
General
342.9%
Active Exploitation
114.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-05-081
Disclosure1
2026-05-093
Active Exploitation1Disclosure1General1
2026-05-132
Disclosure1General1
2026-05-191
General1
Full discourse7 posts
  • はるぷ@harupuxa
    General

    GitHub Actionsの脆弱性を報告して、人生初のCVEを取得した話 (CVE-2026-42298) https://zenn.dev/aeyesec/articles/55fef3bfaab596

    Post summary

    The text announces that a vulnerability in GitHub Actions was reported and assigned CVE-2026-42298, but it provides no additional technical details, PoC, or exploitation information.

    00010158
    496 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Unpopular opinion: The cybersecurity industry is selling you dashboards. CVE: CVE-2026-42298 CVSS: 10 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The post merely lists CVE-2026-42298 with a critical CVSS score, offering basic vulnerability disclosure without any PoC, exploit, or patch information.

    1000041
    210 followersView on X
  • NerdieNews@NewsNerdie
    Active Exploitation

    Postiz CVE-2026-42298 is actively exploited, allowing attackers to execute arbitrary code & exfiltrate tokens via untrusted http://Dockerfile.dev in CI/CD. Patch now to prevent full compromise. #NerdieNews #CyberSecurity #InfoSec #Vulnerability #ZeroTrust #IAM #Kubernetes https://t.co/4Pyid8UoNP

    Post summary

    CVE-2026-42298 is being actively exploited to execute arbitrary code and exfiltrate tokens through untrusted Dockerfiles, and a patch is available to mitigate the risk.

    0001057
    59 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-42298-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The provided statement consists only of a link and hashtags, offering no concrete information about the CVE beyond a reference to an advisory.

    0000027
    210 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-42298 Postiz is an AI social media scheduling tool. Prior to commit da44801, a "Pwn Request" vulnerability in the Build and Publish PR Docker Image workflow (.github/workfl… https://www.cve.org/CVERecord?id=CVE-2026-42298

    Post summary

    The post identifies a CVE associated with a Docker workflow vulnerability in Postiz but lacks detailed technical, exploit, or patch information.

    00000119
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-42298 Unauthenticated Arbitrary Code Execution in Postiz GitHub... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42298 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    An unauthenticated arbitrary code execution vulnerability (CVE-2026-42298) has been disclosed for Postiz's GitHub component; the post lacks details on a PoC, exploit, patch, or active exploitation.

    0000051
    4.0K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🚨 CRITICAL — CVE-2026-42298 Postiz is an AI social media scheduling tool. Prior to commit da44801, a "Pwn Request" vulnerability in the Build and P… CVSS 10.0 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2026-42298 #Docker #CyberSecurity #InfoSec

    Post summary

    The post announces the critical CVE-2026-42298 in Postiz, highlights its CVSS 10.0 rating, notes that no patch is available yet, and links to a detailed analysis.

    0000087
    90 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgitroompostiz---

Explore more