CRITICAL 9.1 GitHub

CVE-2026-53609

Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass

<img width="1919" height="1046" alt="proto" src="https://github.com/user-attachments/assets/c5c69718-6448-448d-b64b-e3db41ab6ff6" /> ## Summary `apos.util.set()` traverses dot-notation paths without sanitizing `__proto__`, allowing an authenticated editor to write arbitrary values to `Object.prototype` via the `$pullAll` patch operator. A confirmed gadget in `publicApiCheck()` causes this to bypass authorization on all piece-type REST API endpoints for every subsequent unauthenticated request

Affected Products

References

Published: 2026-07-31 · Source: GitHub · Feed updated: 2026-08-04
This critical severity vulnerability with a CVSS score of 9.1 was published on 2026-07-31 via GitHub. Affected: npm/apostrophe <= 4.30.0.

Risk Timeline

CVE Disclosed2026-07-31 · 3 days ago

Remediation Resources

Related Vulnerabilities

CVETitleSeverityCVSS
CVE-2026-52887NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCECRITICAL10.0
CVE-2026-69264Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into PCRITICAL
CVE-2026-70470Flowise: Pyodide validator Unicode homoglyph bypass leads to RCECRITICAL
CVE-2025-4318AWS Amplify Studio UI Component Properties Has an Input Validation IssueCRITICAL
CVE-2026-11393AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper TriHIGH9.0
CVE-2026-54639Style Dictionary - Prototype Pollution in convertTokenData utility functionHIGH8.8
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.