Path Traversal Vulnerability in Postiz by Gitroom
CVE-2026-19264
9.3CRITICAL
What is CVE-2026-19264?
Postiz, an open-source social media scheduling tool developed by Gitroom, has a vulnerability that allows unauthenticated remote attackers to exploit the file handling mechanism. The application's upload route improperly manages URL paths, permitting attackers to access any file the application process can read, including sensitive configuration files. This vulnerability potentially exposes secrets like the JWT signing key, database credentials, and connected provider information. The flaw arises from deficiencies in path normalization, allowing attackers to craft URLs that traverse the file system and access sensitive data without authentication, enabling the creation of non-expiring administrative sessions.
Affected Version(s)
postiz-app 0 < 2.22.1
