← العودة للجدول
CVE-2026-53609
CVE-2026-53609 — ApostropheCMS is an open-source Node.js content management system. In versions u
📅 2026-06-12
🔴 Critical 🔥 No NVD Exploit Vulnerability CVSS 9.1

📋 الوصف الكامل

ApostropheCMS is an open-source Node.js content management system. In versions up to and including 4.30.0, `apos.util.set()` traverses dot-notation paths without sanitizing `__proto__`, allowing an authenticated editor to write arbitrary values to `Object.prototype` via the `$pullAll` patch operator. A confirmed gadget in `publicApiCheck()` causes this to bypass authorization on all piece-type RES

💻 الأنظمة المتأثرة

Node.js

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-53609

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v4.30.0

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←