PT-2026-96832 · Postiz · Postiz
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Postiz (affected versions not specified)
Description
Postiz uses
Math.random() instead of a cryptographically secure source to generate security-sensitive credentials. This affects OAuth access tokens, authorization codes, client secrets, organization API keys, and PKCE verifiers, which rely on the deterministic xorshift128+ PRNG (Pseudo-Random Number Generator) state of the V8 engine. An unauthenticated attacker can use a dynamic client registration endpoint to obtain consecutive PRNG outputs and reconstruct the internal state. This allows the attacker to deterministically derive past and future values, potentially compromising credentials of other users and organizations.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Use of Insufficiently Random Values
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Postiz