
Authorized security-research lab reproducing CVE-2026-42298 (pull_request_target docker-build RCE in pr-docker-build.yml) — flattened snapshot of gitroomhq/postiz-app
Automated research artifact — not the upstream project.
This repository is a disposable lab built by an automated harness for a master's thesis at Université Laval on reproducing published GitHub Actions workflow vulnerabilities. It is a verbatim snapshot of
gitroomhq/postiz-appat commite51cae16147be77712a62fbc6fb670ada8a9f385(2026-04-22), redistributed under that project's own licence, whose file is included unchanged in this snapshot.The upstream project is not involved, is never targeted, and the vulnerability studied here is already public. Every secret and variable in this repository is a randomly generated dummy value — no real credential is present. Action references and runner images are pinned to what they resolved to on 2026-04-22; see
pinning.mdin the harness output for every change made to the snapshot.Questions or objections: [email protected]
![]() | ![]() |
|---|---|
![]() | ![]() |
To have the project up and running, please follow the Quick Start Guide
We now give a few options to Sponsor Postiz:
This repository's source code is available under the AGPL-3.0 license.