Skip to main content

CVE-2026-94456: CWE-338 in GitroomHQ postiz-app

0
Critical
VulnerabilityCVE-2026-94456cvecve-2026-94456cwe-338cwe-330cwe-341
Published: 09/22/2026 (09/22/2026, 16:11:33 UTC)
Source: CVE Database V5
Vendor/Project: GitroomHQ
Product: postiz-app

Description

Postiz generates security-sensitive credentials using `Math.random()` instead of a cryptographically secure source. The same helper is used for OAuth access tokens, authorization codes, client secrets, organization API keys, and PKCE verifiers, meaning these credentials depend entirely on V8’s deterministic xorshift128+ PRNG state. An unauthenticated OAuth dynamic client registration endpoint exposes freshly generated client credentials, giving attackers enough consecutive PRNG output to reconstruct that internal state. Once recovered, they can deterministically derive past and future values produced by the same generator, potentially compromising credentials belonging to other users and organizations.

CVSS v3.1

Score 9.1critical

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected software

GitroomHQ

postiz-app

Affected versions
>=0 <2.4.0
GitHub Actionsmore threats →cve
postiz-app
pkg:github/postiz-app
Affected versions
>=0 <2.4.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

Technical Details

Data Version
5.2
Assigner Short Name
postiz
Date Reserved
2026-09-21T17:11:13.201Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6ab2add8f7a7c541066e117a

Added to database: 09/22/2026, 16:33:28 UTC

Last updated: 09/22/2026, 16:33:28 UTC

Views: 1

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses