Postiz, an AI social media scheduling tool, is vulnerable prior to version 2.21.6 to a file upload validation bypass. Any authenticated user can upload arbitrary HTML, SVG, or other executable file types by spoofing the HTTP Content-Type header during upload. The application accepts the file, and nginx subsequently serves the uploaded content using a MIME type derived from the file's original extension, such as text/html or image/svg+xml. As a result, attacker-controlled active content is rendered in the context of the Postiz application origin, creating a stored cross-site scripting condition.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a standalone Python proof-of-concept exploit for CVE-2026-40487 affecting Postiz <= 2.21.5. The repo is small and focused: LICENSE, README.md, requirements.txt, and a single executable script, poc.py. The Python script is the main entry point and uses the requests library plus Python standard modules (argparse, http.server, threading, urllib, json, datetime) to authenticate to a Postiz instance, generate a malicious SVG or HTML payload containing JavaScript, upload it through the vulnerable file upload flow, and start a local HTTP listener to collect exfiltrated data from victims. The exploit chain implemented matches the README description: it abuses server-side trust in attacker-controlled multipart Content-Type, preserves the original dangerous extension on disk, and relies on the application/nginx stack serving uploaded files with extension-derived MIME types. When a victim opens the uploaded file URL, the embedded JavaScript executes in the Postiz origin and can issue authenticated requests with the victim's session. The code is not merely a detector; it supports both a vulnerability check mode and active exploitation mode. Capabilities are extensive and operational rather than minimal. The script contains an attack registry with many actions grouped into exfiltration, privilege escalation, and sabotage. Exfiltration actions include dumping victim profile/org/API key, integrations, posts, team members, media, notifications, signatures, webhooks, OAuth app credentials, billing, settings, third-party configs, autopost rules, sets, tags, customers, and a full-dump mode. Privilege-impacting actions include inviting the attacker as admin and rotating API/OAuth secrets. Sabotage actions include disabling notifications, editing profile data, and deleting various resources. The README also states support for creating a persistent OAuth backdoor token. The exploit can operate using either attacker credentials or an existing Postiz token. Fingerprintable infrastructure in the exploit includes an attacker-controlled exfiltration listener at http://<lhost>:<lport>/loot, bound locally on 0.0.0.0, and victim-facing uploaded payload URLs returned by the target. The README references the vulnerable public uploads path /uploads/ and the nginx MIME configuration file /etc/nginx/mime.types as part of the root cause. Overall, this is a real, weaponizable browser-based stored-XSS exploit with same-origin session-riding effects that can lead to effective account takeover of Postiz users.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.