PT-2026-49006 · Apostrophecms · Apostrophe

Published

2026-06-12

·

Updated

2026-06-12

·

CVE-2026-53609

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
ApostropheCMS is an open-source Node.js content management system. In versions up to and including 4.30.0, apos.util.set() traverses dot-notation paths without sanitizing proto, allowing an authenticated editor to write arbitrary values to Object.prototype via the $pullAll patch operator. A confirmed gadget in publicApiCheck() causes this to bypass authorization on all piece-type REST API endpoints for every subsequent unauthenticated request, for the lifetime of the Node.js process. As of time of publication, no known patched versions are available.

Fix

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2026-53609

Affected Products

Apostrophe