PSA-2026-04-1YDYCVE-2026-42298GCVE-125-2026-04-1YDYApril 24, 2026Arbitrary Code Execution and Token Exfiltration in pr-docker-build.yml via untrusted Dockerfile.dev
Affected (1)
- gitroomhqpostiz-app
- ≥ 0Fixed in 0Affected
All other versions: Unaffected
Mitigations
Exploits
- Full read-write access to the entire postiz-app repo.
Overview
A critical "Pwn Request" vulnerability in the Build and Publish PR Docker Image workflow (.github/workflows/pr-docker-build.yml) allows any unauthenticated user to execute arbitrary code during the Docker build process and exfiltrate a highly privileged GITHUB_TOKEN (write-all permissions). This can be achieved simply by opening a Pull Request from a fork with a maliciously modified Dockerfile.dev.
Severity
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H- Attack Vector
- Network
- Attack Complexity
- Low
- Attack Requirements
- None
- Privileges Required
- None
- User Interaction
- None
- Vuln Confidentiality
- High
- Vuln Integrity
- High
- Vuln Availability
- High
- Sub Confidentiality
- High
- Sub Integrity
- High
- Sub Availability
- High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- Scope
- Changed
- Confidentiality
- High
- Integrity
- High
- Availability
- High
Weaknesses (1)
References (2)
Credits (3)
- smiotani-aeyesecReporter · @smiotani-aeyesec
- Enno GelhausRemediation developer · @egelhaus
- Enno GelhausCoordinator · @egelhaus
Context
Impacts
Attacker gains ability to commit to the repo.
Attacker gains ability to create releases on the repo.
Attacker can close, open, manage PRs / Issues.
Attacker gains full read-write access to all areas of the repo.
Timeline
- 04/22/2026 06:31
Postiz has received the advisory.
- 04/22/2026 08:58
Postiz has acknowledged the advisory.
- 04/22/2026 14:22
Postiz has developed the fix, tested it and published the advisory.
- 04/26/2026 13:09
GitHub has issued CVE-2026-42298 for this Advisory.