Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass — CVE-2026-53609
GitHub · GitHub · CVE-2026-53609
ID
CVE-2026-53609
CVE-2026-53609
Datum
Quelle
GitHub
GitHub
Vendor
GitHub
GitHub
Risiko
critical
critical
Zusammenfassung
<img width="1919" height="1046" alt="proto" src="https://github.com/user-attachments/assets/c5c69718-6448-448d-b64b-e3db41ab6ff6" /> ## Summary `apos.util.set()` traverses dot-notation paths without sanitizing `__proto__`, allowing an authenticated editor to write arbitrary values to `Object.prototype` via the `$pullAll` patch operator. A confirmed gadget in `publicApiCheck()` causes this to bypass authorization on…
Zeitlicher Verlauf
- Von der Quelle veröffentlicht
- 2026-07-31
Risikokontext
- Gemeldeter Schweregrad oder Risikowert: critical.
- Prüfe die Exponierung für das betroffene Produkt oder die Produktfamilie: npm: apostrophe.
Produkt
npm: apostrophe
Was tun?
Allgemeine, vorsichtige Schritte (bitte prüfe die offizielle Quelle für Details):
- Priorisiere sofort Patches oder Mitigations (hohes akutes Risiko).
- Identifiziere betroffene Produktversionen und prüfe, ob du betroffen bist.
- Spiele Hersteller-Updates/Patches ein oder setze empfohlene Mitigations um.
- Lies das offizielle Advisory für betroffene Versionen und konkrete Schritte.
Offizielles Advisory
Nachweise und Herkunft
- Kanonische Advisory-ID
- CVE-2026-53609
- Quelle
- GitHub
- Vendor
- GitHub
- Von der Quelle veröffentlicht
- 2026-07-31
- Letzte Quellenaktivität
- 2026-07-31
- Weitere Kennungen
- GHSA-6H5J-32CF-4253
- Kuratiert von
- hlukh.ch
Verwandte Hinweise und Zusammenhänge
Diese Hinweise sind anhand gemeinsamer CVE-, Produkt-, Hersteller-, Quellen- oder Zeitsignale verknüpft.