HIGH
Postiz allows header mutation in middleware facilitates resulting in SSRF
Published Jul 11, 2025
8.2
HIGHCVSS 3.1
EPSS 0.26%
Description
Postiz is an AI social media scheduling tool. From 1.45.1 to 1.62.3, the Postiz frontend application allows an attacker to inject arbitrary HTTP headers into the middleware pipeline. This flaw enables a server-side request forgery (SSRF) condition, which can be exploited to initiate unauthorized outbound requests from the server hosting the Postiz application. This vulnerability is fixed in 1.62.3.
Affected products
-
- Version >= 1.45.1, < 1.62.3StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Gitroomhq | Postiz-App | n/a |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-21168 Advisory
- https://github.com/gitroomhq/postiz-app/commit/65eca0e2f22155b43c78724ca43617ee52e42753 x_refsource_MISC
- https://github.com/gitroomhq/postiz-app/security/advisories/GHSA-48c8-25jq-m55f x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-21168 | Advisory | |
| https://github.com/gitroomhq/postiz-app/commit/65eca0e2f22155b43c78724ca43617ee52e42753 | x_refsource_MISC | |
| https://github.com/gitroomhq/postiz-app/security/advisories/GHSA-48c8-25jq-m55f | x_refsource_CONFIRM |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jul 11, 2025
Updated Jul 11, 2025
Reserved Jul 7, 2025
Link CVE-2025-53641
CISA Vulnrichment
Updated Jul 11, 2025
ENISA EUVD
EUVD-2025-21168 Assigner GitHub_M
Published Jul 11, 2025
Updated Jul 11, 2025
Exploited since n/a
Link EUVD-2025-21168