Impact
The vulnerability arises because certain Postiz API endpoints return the entire database row for the resources they operate on, rather than limiting the response to the fields required by the client. As a result, callers receive sensitive data that they are not authorized to see, including channel platform access tokens, refresh tokens, and organization API keys. This data leakage can enable an attacker to compromise connected social platform accounts and to impersonate the organization in external services. The weakness is consistent with the CWE-201 ‘Information Exposure Through Disparate Data Sources’ and CWE-213 ‘Improper Verification of Cryptographic Credentials’, which describe comparable patterns of exposing confidential data and mishandling credentials.
Affected Systems
The affected product is GitroomHQ’s Postiz-app. No specific minor versions are enumerated in the CVE, but the published release v2.25.1 contains the fix that removes the leaked fields from the API responses.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated session, API key, or OAuth token and is limited to the caller’s own organization; there is no anonymous or cross‑tenant access. Likely attack vectors involve a third‑party OAuth application that has permission to delete a channel and can thus harvest its credentials, or a lower‑role organization member who can retrieve the organization API key through the GET /user/organizations endpoint. Given the scope and the necessity of valid authentication, the risk to individual tenants is moderate but could be serious if credentials are abused.
OpenCVE Enrichment