CVE-2026-53609
published 2026-06-12CVE-2026-53609: ApostropheCMS is an open-source Node.js content management system. In versions up to and including 4.30.0, `apos.util.set()` traverses dot-notation paths…
PriorityP262critical9.1CVSS 3.1
AVNACLPRLUINSCCHILAL
EPSS
0.38%
29.1th percentile
ApostropheCMS is an open-source Node.js content management system. In versions up to and including 4.30.0, `apos.util.set()` traverses dot-notation paths without sanitizing `__proto__`, allowing an authenticated editor to write arbitrary values to `Object.prototype` via the `$pullAll` patch operator. A confirmed gadget in `publicApiCheck()` causes this to bypass authorization on all piece-type REST API endpoints for every subsequent unauthenticated request, for the lifetime of the Node.js process. As of time of publication, no known patched versions are available.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apostrophecms | apostrophe | <= 4.30.0 | — |
| apostrophecms | apostrophe | >= 0 < 4.31.0 | 4.31.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass
ghsa·2026-07-31
CVE-2026-53609 [CRITICAL] CWE-1321 Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass
Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass
## Summary
`apos.util.set()` traverses dot-notation paths without sanitizing `__proto__`, allowing an authenticated editor to write arbitrary values to `Object.prototype` via the `$pullAll` patch operator.
A confirmed gadget in `publicApiCheck()` causes this to bypass authorization on all piece-type REST API endpoints for every subsequent unauthenticated request, for the lifetime of the Node.js process.
---
## Details
### Root Cause — `apos.util.set()` (`modules/@apostrophecms/util/index.js` ~line 800)
The function splits a dot-notation path and traverses properties without rejecting `__proto__`, `constructor`, or `prototype`:
```js
set(o, path, v) {
VulDB
apostrophecms apostrophe up to 4.30.0 REST API Endpoint apos.util.set pullAll prototype pollution (GHSA-6h5j-32cf-4253)
vuldb·2026-06-13·CVSS 9.1
CVE-2026-53609 [CRITICAL] apostrophecms apostrophe up to 4.30.0 REST API Endpoint apos.util.set pullAll prototype pollution (GHSA-6h5j-32cf-4253)
A vulnerability classified as critical has been found in apostrophecms apostrophe up to 4.30.0. Affected by this issue is the function apos.util.set of the component REST API Endpoint. This manipulation of the argument pullAll causes improperly controlled modification of object prototype attributes.
The identification of this vulnerability is CVE-2026-53609. It is possible to initiate the attack remotely. There is no exploit available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-12
Published