highCVSS 7.5Vulnerability
GHSA-vj2p-7pgw-g2wf
### Impact A successful SSRF attack allows an attacker to: - Bypass firewalls to scan and interact with internal network services/ports. - Access sensitive cloud metadata services (e.g., AWS IMDS 169.254.169.254) to potentially leak instance credentials. - Pivot into the internal network environment where Postiz is hosted. ### Workarounds There are no workarounds known to this, please upgrade to Postiz version `v2.21.1`.
Properties
- ghsa_id
- GHSA-vj2p-7pgw-g2wf
- severity
- high
- summary
- Postiz App has a High-Severity SSRF Vulnerability via Next.js
- cvss_score
- 7.5
- cve_id
- GHSA-vj2p-7pgw-g2wf
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- is_ghsa_only
- true
- ghsa_published
- 2026-03-27T15:46:53Z
- source_url
- https://github.com/advisories/GHSA-vj2p-7pgw-g2wf
- ghsa_updated
- 2026-03-27T15:46:54Z
Related Entities (4)
AFFECTS (1)
→[Software]npm/postiz
HAS_WEAKNESS (2)
→[Weakness]Dependency on Vulnerable Third-Party Component
→[Weakness]Server-Side Request Forgery (SSRF)
REPORTED_BY (1)
→[Source]GitHub Advisory Database
Explore deeper with Ninja Signal's threat intelligence graph