Postiz · Vulnerability Disclosure

Postiz Vulnerability Disclosure

Vulnerability disclosure

Postiz publishes a vulnerability disclosure policy for reporting security issues. A dedicated security contact is published.

Social-MediaSchedulingOpen-SourceContentMarketingAgentsMCPAutomationPublishingAnalytics
Program:

Disclosure Policy

Policy
Policy

Security Contact

Contact
egelhaus@ennogelhaus.de

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-13'
method: searched
probe: true
source: https://github.com/gitroomhq/postiz-app/blob/main/SECURITY.md
note: >-
  probe-security-programs.py found nothing (vdp=none) because Postiz serves no
  /.well-known/security.txt and no /security page on postiz.com. The program is real
  and substantial — it lives in the repository SECURITY.md and on a dedicated advisory
  platform. This artifact is the searched upgrade over the empty probe.
policy:
- https://github.com/gitroomhq/postiz-app/blob/main/SECURITY.md
- https://postiz.gadvisory.org/advisories
report_intake:
- https://postiz.gadvisory.org/request
contact:
- egelhaus@ennogelhaus.de
contact_note: >-
  Maintainer email is for urgent reports only; all routine security correspondence goes
  through the GAdvisory request form. GitHub private vulnerability reporting is
  DISABLED for gitroomhq repositories — GitHub Security Advisories are a publishing
  mirror only.
bug_bounty:
  program: false
  platform: null
  note: No paid bounty. Coordinated disclosure with credit in the published advisory and CVE record.
cna:
  is_cna: true
  scope: Products listed in the SECURITY.md scope section
  lifecycle: Reserve on confirmation, share the reserved ID with the reporter, publish with the advisory and the fixed release
  advisories: https://postiz.gadvisory.org/advisories
  note: >-
    Postiz operates as a CVE Numbering Authority for its own products — an unusually
    mature posture for a company of this size, and a stronger signal than a security.txt.
scope:
  in_scope:
  - github.com/gitroomhq/postiz-app core repository
  - All gitroomhq repositories that are official Postiz components, tooling or integrations
  - Official Postiz container images on GHCR under gitroomhq
  - Official Postiz CLI tools and npm packages (npm org @postiz)
  - Postiz Cloud infrastructure and services (API, frontend, configuration)
  - Plugins maintained within the gitroomhq organization
  out_of_scope:
  - Third-party dependencies unless Postiz's own use is independently exploitable
  - User-hosted infrastructure misconfiguration on self-hosted instances
  - Denial-of-service, brute force and resource exhaustion absent a missing common defense
  - Social engineering, phishing, self-XSS
  - Missing hardening with no demonstrated exploitable impact
  - End-of-life or unsupported versions
disclosure_model: coordinated (private until a fix or mitigation ships)
timelines:
  initial_acknowledgment: 72 hours
  triage_verification: 7 days after acknowledgment
  critical_remediation: 90 days after triage
  non_critical_remediation: 180 days after triage
  cve_publication: within 24 hours of the remediation release
ai_reports_policy: >-
  LLM-generated reports without meaningful human analysis — typically lacking a working
  proof of concept, reproducible steps or accurate impact assessment — are closed
  without detailed response. AI-assisted analysis is welcome when validated by the
  reporter with a PoC, repro steps and impact assessment.
recent_advisory_example:
  id: PSA-2026-NWZN9J
  fixed_in: v2.21.10
  released: '2026-06-22'
  source: https://github.com/gitroomhq/postiz-app/releases
security_txt:
  served: false
  note: >-
    Recommendation for the provider — publish /.well-known/security.txt on postiz.com
    and api.postiz.com with Policy and Contact pointing at the GAdvisory form. The
    program already exists; only the RFC 9116 advertisement is missing.
evidence:
- {source: 'https://raw.githubusercontent.com/gitroomhq/postiz-app/main/SECURITY.md', status: 200, kind: security-policy, fetched: '2026-08-13'}
- {source: 'https://postiz.gadvisory.org/request', status: 200, kind: disclosure-intake, fetched: '2026-08-13'}
- {source: 'https://postiz.gadvisory.org/advisories', status: 200, kind: advisory-database, fetched: '2026-08-13'}
- {source: 'https://postiz.com/.well-known/security.txt', status: 404, kind: security-txt, fetched: '2026-08-13'}
- {source: 'https://api.postiz.com/.well-known/security.txt', status: 404, kind: security-txt, fetched: '2026-08-13'}
trust_center:
  present: false
  note: >-
    trust.postiz.com and security.postiz.com do not resolve; postiz.com/security and
    postiz.com/compliance both return 404. No trust-center artifact is written and no
    TrustCenter or Compliance pointer is emitted.
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com