CRITICAL 9.1 GitHub
CVE-2026-53609
Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass
<img width="1919" height="1046" alt="proto" src="https://github.com/user-attachments/assets/c5c69718-6448-448d-b64b-e3db41ab6ff6" />
## Summary
`apos.util.set()` traverses dot-notation paths without sanitizing `__proto__`, allowing an authenticated editor to write arbitrary values to `Object.prototype` via the `$pullAll` patch operator.
A confirmed gadget in `publicApiCheck()` causes this to bypass authorization on all piece-type REST API endpoints for every subsequent unauthenticated request
Affected Products
- npm/apostrophe <= 4.30.0
References
- https://github.com/advisories/GHSA-6h5j-32cf-4253
- https://github.com/apostrophecms/apostrophe/security/advisories/GHSA-6h5j-32cf-4253
- https://nvd.nist.gov/vuln/detail/CVE-2026-53609
- https://github.com/apostrophecms/apostrophe/pull/5464
This critical severity vulnerability with a CVSS score of 9.1 was published on 2026-07-31 via GitHub. Affected: npm/apostrophe <= 4.30.0.
Risk Timeline
CVE Disclosed2026-07-31 · 3 days ago
Remediation Resources
NVD / MITRE
nvd.nist.gov/vuln/detail/CVE-2026-53609Related Vulnerabilities
| CVE | Title | Severity | CVSS |
|---|---|---|---|
| CVE-2026-52887 | NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE | CRITICAL | 10.0 |
| CVE-2026-69264 | Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into P | CRITICAL | — |
| CVE-2026-70470 | Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE | CRITICAL | — |
| CVE-2025-4318 | AWS Amplify Studio UI Component Properties Has an Input Validation Issue | CRITICAL | — |
| CVE-2026-11393 | AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Tri | HIGH | 9.0 |
| CVE-2026-54639 | Style Dictionary - Prototype Pollution in convertTokenData utility function | HIGH | 8.8 |
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.