HIGH7.5
GHSA-vj2p-7pgw-g2wf
Postiz App has a High-Severity SSRF Vulnerability via Next.js
Details
### Impact A successful SSRF attack allows an attacker to: - Bypass firewalls to scan and interact with internal network services/ports. - Access sensitive cloud metadata services (e.g., AWS IMDS 169.254.169.254) to potentially leak instance credentials. - Pivot into the internal network environment where Postiz is hosted.
### Workarounds There are no workarounds known to this, please upgrade to Postiz version `v2.21.1`.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/postiz
Introduced in:
0No fixed version published yet for postiz (npm). Pin to a known-safe version or switch to an alternative.