CVE-2026-71553High▾ TwilightApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 2.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.3%
Last analysed / modified upstream
The vulnerability is a single-request persistent DoS by submitting e.g. "PATCH /api/v1/article/<id>" with a valid editor session and body of {"toString.call":"x"}, overwriting the global toString function with value x.
Fabian
apostrophe <= 4.32.0Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-53609Critical· 9.1Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass
CVE-2026-63669Medium· 6.5ApostropheCMS is an open-source Node.js content management system
CVE-2026-53607Low· 3.7@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header
CVE-2026-61534Critical· 9.1Yayson is a library for serializing and reading JSON API data in JavaScript
CVE-2026-86078Medium· 6.5n8n is an open source workflow automation platform
CVE-2026-84367Low· 3.7joi is a schema description language and data validator for JavaScript