๐Ÿ” CVE Alert

CVE-2026-45012

HIGH 7.6

Apostrophe has authenticated SSRF in rich-text widget import via @apostrophecms/area/validate-widget

CVSS Score
7.6
EPSS Score
0.0%
EPSS Percentile
13th

ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 contain an authenticated server-side request forgery (SSRF) in the rich-text widget import flow. An authenticated user who can submit/edit rich-text widget content can cause the server to fetch attacker-controlled URLs during widget validation. For image-compatible responses, the fetched content can be persisted and re-hosted by Apostrophe, allowing response exfiltration. As of time of publication, no known patched versions are available.

CWE CWE-918
Vendor apostrophecms
Product apostrophe
Published Jun 12, 2026
Stay Ahead of the Next One

Get instant alerts for apostrophecms apostrophe

Be the first to know when new high vulnerabilities affecting apostrophecms apostrophe are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
Low

Affected Versions

apostrophecms / apostrophe
<= 4.29.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/apostrophecms/apostrophe/security/advisories/GHSA-pr28-mf3q-qpg6