VDB
Sign up
HIGH7.5

GHSA-vj2p-7pgw-g2wf

Postiz App has a High-Severity SSRF Vulnerability via Next.js

Details

### Impact A successful SSRF attack allows an attacker to: - Bypass firewalls to scan and interact with internal network services/ports. - Access sensitive cloud metadata services (e.g., AWS IMDS 169.254.169.254) to potentially leak instance credentials. - Pivot into the internal network environment where Postiz is hosted.

### Workarounds There are no workarounds known to this, please upgrade to Postiz version `v2.21.1`.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/postiz
Introduced in: 0

No fixed version published yet for postiz (npm). Pin to a known-safe version or switch to an alternative.

References