CVE-2026-42298

CRITICAL

Postiz is an AI social media scheduling tool. Prior to commit da44801, a "Pwn Request" vulnerability in the Build and Publish PR Docker Image workflow (.github/workflows/pr-docker-build.yml) allows...

Affects 0 products across 3 vendors.

BCS6.79
CVSS 3.19.8
EPSS0.5%
Percentile41th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-94: Code Injection

Attacker injects arbitrary code that is executed by the application process.

Related Attack Patterns (CAPEC)
CAPEC-35 Leverage Executable Code in Non-Executable Files
via CWE-94
CAPEC-77 Manipulating User-Controlled Variables
via CWE-94
CAPEC-242 Code Injection
via CWE-94

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A critical vulnerability in Postiz's Build and Publish PR Docker Image workflow allows unauthenticated users to execute arbitrary code and exfiltrate a highly privileged GITHUB_TOKEN.

BSID: BS-2026-GLOBAL-186730-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-42298?
A critical vulnerability in Postiz's Build and Publish PR Docker Image workflow allows unauthenticated users to execute arbitrary code and exfiltrate a highly privileged GITHUB_TOKEN.
What is the CVSS score for CVE-2026-42298?
CVE-2026-42298 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 0.5%.
Is CVE-2026-42298 actively exploited?
No confirmed active exploitation of CVE-2026-42298 as of 2026-06-02.
How do I remediate CVE-2026-42298?
Priority: IMMEDIATE.
What systems are affected by CVE-2026-42298?
CVE-2026-42298 affects: Docker, Github, Modified.
Vulnerability Details
CVE IDCVE-2026-42298
BSIDBS-2026-GLOBAL-186730-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2026-05-08
Last Modified2026-06-01
ICS Relevance15%
Weakness (CWE)
Domains
CLOUD
SourceNVD
Official Description

Postiz is an AI social media scheduling tool. Prior to commit da44801, a "Pwn Request" vulnerability in the Build and Publish PR Docker Image workflow (.github/workflows/pr-docker-build.yml) allows any unauthenticated user to execute arbitrary code during the Docker build process and exfiltrate a highly privileged GITHUB_TOKEN (write-all permissions). This can be achieved simply by opening a Pull Request from a fork with a maliciously modified Dockerfile.dev. This issue has been patched via commit da44801.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability exists in the .github/workflows/pr-docker-build.yml file prior to commit da44801. An attacker can exploit this by opening a Pull Request, which triggers the vulnerable workflow and allows for arbitrary code execution and token exfiltration.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Docker —
Github —
Modified —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 113 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hashf9cbfbd5ff4d47bd5062c28d9a4c8264c9b30df0f82090a037d433af4d2ec58cd5adc2415807fb8fb382de26f73528d827ed1b1a3c9769ae4cc9e7c4ac6389b2
Related CVEs affecting Docker
CVE-2024-29895 10.0 Cacti provides an operational monitoring and fault management framework. A co... CVE-2014-9357 10.0 Docker 1.3.2 allows remote attackers to execute arbitrary code with root priv... CVE-2026-42869 10.0 SOCFortress CoPilot focuses on providing a single pane of glass for all your ... CVE-2026-40089 9.9 Sonicverse is a Self-hosted Docker Compose stack for live radio streaming. Th... CVE-2026-42454 9.9 Termix is a web-based server management platform with SSH terminal, tunneling...
View all Docker CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →