CyberRota Analysis
AI-GeneratedThe vulnerability arises from Postiz's use of `Math.random()` for generating security-sensitive credentials, including OAuth tokens and API keys, which are instead expected to be generated by a cryptographically secure source. This flaw allows unauthenticated attackers to exploit a dynamic client registration endpoint, enabling them to reconstruct the internal state of the pseudo-random number generator and derive sensitive credentials for other users and organizations. Organizations utilizing Postiz for OAuth or API key management should prioritize addressing this critical vulnerability to mitigate the risk of credential compromise.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Postiz generates security-sensitive credentials using `Math.random()` instead of a cryptographically secure source. The same helper is used for OAuth access tokens, authorization codes, client secrets, organization API keys, and PKCE verifiers, meaning these credentials depend entirely on V8’s deterministic xorshift128+ PRNG state. An unauthenticated OAuth dynamic client registration endpoint exposes freshly generated client credentials, giving attackers enough consecutive PRNG output to reconstruct that internal state. Once recovered, they can deterministically derive past and future values produced by the same generator, potentially compromising credentials belonging to other users and organizations.