CVE-2025-53641: Postiz allows header mutation in middleware facilitates resulting in SSRF
Postiz is an AI social media scheduling tool. From 1.45.1 to 1.62.3, the Postiz frontend application allows an attacker to inject arbitrary HTTP headers into the middleware pipeline. This flaw enables a server-side request forgery (SSRF) condition, which can be exploited to initiate unauthorized outbound requests from the server hosting the Postiz application. This vulnerability is fixed in 1.62.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53641?
CVE-2025-53641 has been rated as a critical severity vulnerability due to its potential for server-side request forgery (SSRF).
How do I fix CVE-2025-53641?
To fix CVE-2025-53641, upgrade your Postiz application to version 1.62.4 or later, where the vulnerability has been addressed.
What types of systems are affected by CVE-2025-53641?
CVE-2025-53641 affects Postiz versions from 1.45.1 to 1.62.3.
What impact does CVE-2025-53641 have on my data security?
CVE-2025-53641 allows attackers to inject arbitrary HTTP headers, potentially compromising sensitive data through SSRF.
Can CVE-2025-53641 be exploited remotely?
Yes, CVE-2025-53641 can be exploited remotely, enabling attackers to interact with internal server resources.