highCVSS 7.5Vulnerability

GHSA-vj2p-7pgw-g2wf

### Impact A successful SSRF attack allows an attacker to: - Bypass firewalls to scan and interact with internal network services/ports. - Access sensitive cloud metadata services (e.g., AWS IMDS 169.254.169.254) to potentially leak instance credentials. - Pivot into the internal network environment where Postiz is hosted. ### Workarounds There are no workarounds known to this, please upgrade to Postiz version `v2.21.1`.

Properties

ghsa_id
GHSA-vj2p-7pgw-g2wf
severity
high
summary
Postiz App has a High-Severity SSRF Vulnerability via Next.js
cvss_score
7.5
cve_id
GHSA-vj2p-7pgw-g2wf
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
is_ghsa_only
true
ghsa_published
2026-03-27T15:46:53Z
source_url
https://github.com/advisories/GHSA-vj2p-7pgw-g2wf
ghsa_updated
2026-03-27T15:46:54Z

Related Entities (4)

AFFECTS (1)

[Software]npm/postiz

HAS_WEAKNESS (2)

[Weakness]Dependency on Vulnerable Third-Party Component
[Weakness]Server-Side Request Forgery (SSRF)

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph