CVE-2026-71553
ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
ApostropheCMS is an open-source Node.js content management system. In 4.32.0 and earlier, PATCH /api/v1/article/:id accepts the inherited path toString.call and passes it through the utility module to apos.util.set() and apos.util.get(), allowing an authenticated editor to overwrite the shared Object.prototype.toString function's call property and cause a persistent process-wide denial of service until restart.
| CWE | CWE-1321 |
| Vendor | apostrophecms |
| Product | apostrophe |
| Published | Aug 17, 2026 |
| Last Updated | Aug 17, 2026 |
Stay Ahead of the Next One
Get instant alerts for apostrophecms apostrophe
Be the first to know when new unknown vulnerabilities affecting apostrophecms apostrophe are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
apostrophecms / apostrophe
<= 4.32.0