Path Traversal Vulnerability in Postiz by Gitroom
CVE-2026-19264
Key Information:
- Vendor
Gitroomhq
- Status
- Vendor
- CVE Published:
- 7 August 2026
Badges
What is CVE-2026-19264?
Postiz, an open-source social media scheduling tool developed by Gitroom, has a vulnerability that allows unauthenticated remote attackers to exploit the file handling mechanism. The application's upload route improperly manages URL paths, permitting attackers to access any file the application process can read, including sensitive configuration files. This vulnerability potentially exposes secrets like the JWT signing key, database credentials, and connected provider information. The flaw arises from deficiencies in path normalization, allowing attackers to craft URLs that traverse the file system and access sensitive data without authentication, enabling the creation of non-expiring administrative sessions.
Affected Version(s)
postiz-app 0 < 2.22.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
