CVE-2021-33570

MEDIUM

Postbird 0.8.4 - Stored Cross-Site Scripting via IMG onerror Attribute

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2021-33570. PoCs published by Debshubra Chakraborty.

AI-analyzed exploit summary This exploit demonstrates a JavaScript injection vulnerability in Postbird 0.8.4, allowing XSS, LFI, and credential theft via crafted payloads. It includes a Python server to exfiltrate data from the victim's machine.

Description

Postbird 0.8.4 allows stored XSS via the onerror attribute of an IMG element in any PostgreSQL database table. This can result in reading local files via vectors involving XMLHttpRequest and open of a file:/// URL, or discovering PostgreSQL passwords via vectors involving Window.localStorage and savedConnections.

Exploits (1)

exploitdb WORKING POC
by Debshubra Chakraborty · pythonwebappsmultiple
https://www.exploit-db.com/exploits/49910

This exploit demonstrates a JavaScript injection vulnerability in Postbird 0.8.4, allowing XSS, LFI, and credential theft via crafted payloads. It includes a Python server to exfiltrate data from the victim's machine.

Classification
Working Poc 95%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Postbird 0.8.4
No auth needed
Prerequisites: Victim must execute the crafted payload in Postbird
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Issue Tracking, Third Party Advisory x_refsource_misc
https://github.com/Paxa/postbird/issues/132
Issue Tracking, Third Party Advisory x_refsource_misc
https://github.com/Paxa/postbird/issues/133
Issue Tracking, Third Party Advisory x_refsource_misc
https://github.com/Paxa/postbird/issues/134
Exploit, Third Party Advisory x_refsource_misc
https://github.com/Tridentsec-io/postbird
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
https://www.exploit-db.com/exploits/49910
Broken Link, Third Party Advisory, URL Repurposed x_refsource_misc
https://tridentsec.io/blogs/postbird-cve-2021-33570/

Scores

CVSS v3 5.4
EPSS 0.0356
EPSS Percentile 87.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
postbird_project/postbird 0.8.4
Published May 25, 2021
Tracked Since Feb 18, 2026