CVE-2026-42298
Postiz is an AI social media scheduling tool. Prior to commit da44801, a "Pwn Request" vulnerability in the Build and Publish PR Docker Image workflow (.github/workflows/pr-docker-build.yml) allows...
Affects 0 products across 3 vendors.
Attacker injects arbitrary code that is executed by the application process.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
A critical vulnerability in Postiz's Build and Publish PR Docker Image workflow allows unauthenticated users to execute arbitrary code and exfiltrate a highly privileged GITHUB_TOKEN.
BSID: BS-2026-GLOBAL-186730-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2026-42298?
What is the CVSS score for CVE-2026-42298?
Is CVE-2026-42298 actively exploited?
How do I remediate CVE-2026-42298?
What systems are affected by CVE-2026-42298?
| CVE ID | CVE-2026-42298 |
|---|---|
| BSID | BS-2026-GLOBAL-186730-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Published | 2026-05-08 |
| Last Modified | 2026-06-01 |
| ICS Relevance | 15% |
| Weakness (CWE) | |
| Domains | |
| Source | NVD |
Postiz is an AI social media scheduling tool. Prior to commit da44801, a "Pwn Request" vulnerability in the Build and Publish PR Docker Image workflow (.github/workflows/pr-docker-build.yml) allows any unauthenticated user to execute arbitrary code during the Docker build process and exfiltrate a highly privileged GITHUB_TOKEN (write-all permissions). This can be achieved simply by opening a Pull Request from a fork with a maliciously modified Dockerfile.dev. This issue has been patched via commit da44801.
Source: NIST NVD / MITRE CVE Database
The vulnerability exists in the .github/workflows/pr-docker-build.yml file prior to commit da44801. An attacker can exploit this by opening a Pull Request, which triggers the vulnerable workflow and allows for arbitrary code execution and token exfiltration.
Exploitation Likelihood: CRITICAL
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | f9cbfbd5ff4d47bd5062c28d9a4c8264c9b30df0f82090a037d433af4d2ec58cd5adc2415807fb8fb382de26f73528d827ed1b1a3c9769ae4cc9e7c4ac6389b2 |
Critical Severity - Know Your Exposure
A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →