CVE-2026-42298Gitroom · Postiz
Vulnerability data via NVD (ingested)
Postiz is an AI social media scheduling tool. Prior to commit da44801, a "Pwn Request" vulnerability in the Build and Publish PR Docker Image workflow (.github/workflows/pr-docker-build.yml) allows any unauthenticated user to execute arbitrary code during the Docker build process and exfiltrate a highly privileged GITHUB_TOKEN (write-all permissions). This can be achieved simply by opening a Pull Request from a fork with a maliciously modified Dockerfile.dev. This issue has been patched via commit da44801.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-42298product:"Gitroom Postiz"http.html:"Postiz"More intel sources (5)
vuln:CVE-2026-42298vulnerabilities.cve_id: CVE-2026-42298CVE-2026-42298CVE-2026-42298"CVE-2026-42298" exploit -site:nvd.nist.gov