Server-Side Request Forgery Vulnerability in Postiz AI Social Media Tool
CVE-2025-53641
8.2HIGH
What is CVE-2025-53641?
The Postiz application, an AI-driven social media scheduling tool, contains a vulnerability that allows attackers to inject arbitrary HTTP headers. This issue affects versions ranging from 1.45.1 to 1.62.3. By exploiting this flaw, an attacker can initiate unauthorized outbound requests from the server that hosts the application, potentially leading to data breaches and further unauthorized access. Users are advised to upgrade to version 1.62.3 to mitigate risks associated with this vulnerability.
Affected Version(s)
postiz-app >= 1.45.1, < 1.62.3