CVE-2026-42556
Postiz allows attackers to steal customer data via malicious links
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
The Postiz AI scheduling tool has a flaw allowing authenticated users to embed malicious HTML in posts, which can then be executed when shared via a preview link, potentially exposing sensitive data. Update to version 2.21.7 to fix this.