HIGH 7.1 NVD
CVE-2026-71553
ApostropheCMS is an open-source Node.js content management system. In 4.32.0 and earlier, PATCH /api/v1/article/:id accepts the inherited path toString.call and
ApostropheCMS is an open-source Node.js content management system. In 4.32.0 and earlier, PATCH /api/v1/article/:id accepts the inherited path toString.call and passes it through the utility module to apos.util.set() and apos.util.get(), allowing an authenticated editor to overwrite the shared Object.prototype.toString function's call property and cause a persistent process-wide denial of service until restart.
References
- https://github.com/apostrophecms/apostrophe/commit/5a3746aaed49761e171c2cbfe793267c959829f
- https://github.com/apostrophecms/apostrophe/security/advisories/GHSA-vmg4-6gfg-83qx
This high severity vulnerability with a CVSS score of 7.1 was published on 2026-08-17 via NVD.
vulnfeed aggregates 11030 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.