Vulnerability in Postiz AI Tool Allows Code Execution via Docker Build

⚠️ CVE-Referenzen: CVE-2026-42298
Gitroomhq - Postiz-app - CRITICAL - CVE-2026-42298. A vulnerability in the Postiz AI social media scheduling tool allows unauthenticated users to execute arbitrary code during the Docker build process. This is made possible through the Build and Publish PR Docker Image workflow, which can be exploited by submitting a Pull Request containing a maliciously modified Dockerfile.dev. The exploitation of this vulnerability can lead to the exfiltration of a highly privileged GITHUB_TOKEN with write-all permissions. The issue has been addressed in commit da44801.
Quelle: securityvulnerability.io