HIGH 8.7 GitHub
CVE-2026-53608
@apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag
<img width="1919" height="1046" alt="curl" src="https://github.com/user-attachments/assets/8aa19ff1-7f4b-44ee-83d5-d0dd1a0269f6" />
<img width="1919" height="775" alt="xss" src="https://github.com/user-attachments/assets/a65012e8-9b2f-416f-94df-c00493f2ca1d" />
### Summary
The `@apostrophecms/seo` package injects the Google Analytics Tracking ID (`seoGoogleTrackingId`) and Google Tag Manager ID (`seoGoogleTagManager`) directly into `<script>` tag bodies using JavaScript template literals witho
Affected Products
- npm/@apostrophecms/seo <= 1.4.2
References
- https://github.com/advisories/GHSA-wf43-fpp3-cf65
- https://github.com/apostrophecms/apostrophe/security/advisories/GHSA-wf43-fpp3-cf65
- https://nvd.nist.gov/vuln/detail/CVE-2026-53608
- https://github.com/apostrophecms/apostrophe/pull/5464
This high severity vulnerability with a CVSS score of 8.7 was published on 2026-07-31 via GitHub. Affected: npm/@apostrophecms/seo <= 1.4.2.
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.