Postiz · Vulnerability Disclosure
Postiz Vulnerability Disclosure
Vulnerability disclosure
Postiz publishes a vulnerability disclosure policy for reporting security issues. A dedicated security contact is published.
Social-MediaSchedulingOpen-SourceContentMarketingAgentsMCPAutomationPublishingAnalytics
Program:
Disclosure Policy
Policy
Policy
Security Contact
Contact
egelhaus@ennogelhaus.de
Source
Vulnerability Disclosure
generated: '2026-08-13'
method: searched
probe: true
source: https://github.com/gitroomhq/postiz-app/blob/main/SECURITY.md
note: >-
probe-security-programs.py found nothing (vdp=none) because Postiz serves no
/.well-known/security.txt and no /security page on postiz.com. The program is real
and substantial — it lives in the repository SECURITY.md and on a dedicated advisory
platform. This artifact is the searched upgrade over the empty probe.
policy:
- https://github.com/gitroomhq/postiz-app/blob/main/SECURITY.md
- https://postiz.gadvisory.org/advisories
report_intake:
- https://postiz.gadvisory.org/request
contact:
- egelhaus@ennogelhaus.de
contact_note: >-
Maintainer email is for urgent reports only; all routine security correspondence goes
through the GAdvisory request form. GitHub private vulnerability reporting is
DISABLED for gitroomhq repositories — GitHub Security Advisories are a publishing
mirror only.
bug_bounty:
program: false
platform: null
note: No paid bounty. Coordinated disclosure with credit in the published advisory and CVE record.
cna:
is_cna: true
scope: Products listed in the SECURITY.md scope section
lifecycle: Reserve on confirmation, share the reserved ID with the reporter, publish with the advisory and the fixed release
advisories: https://postiz.gadvisory.org/advisories
note: >-
Postiz operates as a CVE Numbering Authority for its own products — an unusually
mature posture for a company of this size, and a stronger signal than a security.txt.
scope:
in_scope:
- github.com/gitroomhq/postiz-app core repository
- All gitroomhq repositories that are official Postiz components, tooling or integrations
- Official Postiz container images on GHCR under gitroomhq
- Official Postiz CLI tools and npm packages (npm org @postiz)
- Postiz Cloud infrastructure and services (API, frontend, configuration)
- Plugins maintained within the gitroomhq organization
out_of_scope:
- Third-party dependencies unless Postiz's own use is independently exploitable
- User-hosted infrastructure misconfiguration on self-hosted instances
- Denial-of-service, brute force and resource exhaustion absent a missing common defense
- Social engineering, phishing, self-XSS
- Missing hardening with no demonstrated exploitable impact
- End-of-life or unsupported versions
disclosure_model: coordinated (private until a fix or mitigation ships)
timelines:
initial_acknowledgment: 72 hours
triage_verification: 7 days after acknowledgment
critical_remediation: 90 days after triage
non_critical_remediation: 180 days after triage
cve_publication: within 24 hours of the remediation release
ai_reports_policy: >-
LLM-generated reports without meaningful human analysis — typically lacking a working
proof of concept, reproducible steps or accurate impact assessment — are closed
without detailed response. AI-assisted analysis is welcome when validated by the
reporter with a PoC, repro steps and impact assessment.
recent_advisory_example:
id: PSA-2026-NWZN9J
fixed_in: v2.21.10
released: '2026-06-22'
source: https://github.com/gitroomhq/postiz-app/releases
security_txt:
served: false
note: >-
Recommendation for the provider — publish /.well-known/security.txt on postiz.com
and api.postiz.com with Policy and Contact pointing at the GAdvisory form. The
program already exists; only the RFC 9116 advertisement is missing.
evidence:
- {source: 'https://raw.githubusercontent.com/gitroomhq/postiz-app/main/SECURITY.md', status: 200, kind: security-policy, fetched: '2026-08-13'}
- {source: 'https://postiz.gadvisory.org/request', status: 200, kind: disclosure-intake, fetched: '2026-08-13'}
- {source: 'https://postiz.gadvisory.org/advisories', status: 200, kind: advisory-database, fetched: '2026-08-13'}
- {source: 'https://postiz.com/.well-known/security.txt', status: 404, kind: security-txt, fetched: '2026-08-13'}
- {source: 'https://api.postiz.com/.well-known/security.txt', status: 404, kind: security-txt, fetched: '2026-08-13'}
trust_center:
present: false
note: >-
trust.postiz.com and security.postiz.com do not resolve; postiz.com/security and
postiz.com/compliance both return 404. No trust-center artifact is written and no
TrustCenter or Compliance pointer is emitted.
maintainers:
- FN: Kin Lane
email: kin@apievangelist.com