{"id":"CVE-2026-42853","aliases":["GHSA-hcwq-x9fw-8cfq"],"url":"https://o3.security/vulnerability/CVE-2026-42853","summary":"@apostrophecms/cli: Command Injection in apos create via Unsanitized Password Input","details":"Summary\n\nThe @apostrophecms/cli package contains a command injection vulnerability in the apos create command.\nUser-supplied input from the password prompt is embedded directly into a shell command without proper sanitization or escaping.\nThis allows execution of arbitrary commands on the host system.\n\n━━━━━━━━━━━━━━━━━━━━━━\n\nDetails\n\nVulnerable file: lib/commands/create.js\nLocation: Line 186\n\nThe CLI collects a password using an interactive prompt and passes it directly into a shell command.\n\nVulnerable code:\n\nconst response = await prompts({\ntype: 'password',\nname: 'pw',\nmessage: '🔏 Please enter a password:'\n});\n\nexec(echo \"${response.pw}\" | ${createUserCommand});\n\nThe value of response.pw is not validated, sanitized, or escaped before being used in exec().\n\nThis allows shell metacharacters such as ;, &&, and $() to break out of the intended command and execute arbitrary commands.\n\n━━━━━━━━━━━━━━━━━━━━━━\n\nSteps to Reproduce\n\n1) Install the CLI\n      npm install -g @apostrophecms/cli\n2) Create a new project\n      mkdir testproject && cd testproject\n      apos create mysite\n3)When prompted for the admin password, enter\n      \"; id > /tmp/apos_rce_proof.txt; echo \"\n4)Verify command execution\n        cat /tmp/apos_rce_proof.txt\n\n━━━━━━━━━━━━━━━━━━━━━━\n\nProof of Concept Output\n\nuid=1000(vboxuser) gid=1000(vboxuser) groups=1000(vboxuser),27(sudo),984(docker)\n\nThis confirms arbitrary command execution with the privileges of the user running the CLI.\n\n━━━━━━━━━━━━━━━━━━━━━━\n\nImpact\n\nArbitrary command execution on the developer’s machine\nExecution occurs with the privileges of the user running the CLI\n\nThis can lead to:\n\nFile modification or deletion\nCredential exposure\nSystem compromise depending on user privileges\n\nAn attacker can exploit this by influencing the password input (for example, through social engineering, malicious documentation, or compromised automation scripts).\n\nThe proof-of-concept shows execution under a user belonging to privileged groups such as sudo and docker, which may allow further privilege escalation depending on system configuration.\n\n━━━━━━━━━━━━━━━━━━━━━━\n\nSuggested Fix\n\nAvoid using exec() with user-controlled input.\n\nUse execFile() instead:\n\nconst { execFileSync } = require('child_process');\n\nexecFileSync('node', [appJsPath, userTask, 'admin', 'admin'], {\ninput: response.pw + '\\n'\n});\n\n━━━━━━━━━━━━━━━━━━━━━━\n\nAffected Version\n\nAll current versions of @apostrophecms/cli\n\n━━━━━━━━━━━━━━━━━━━━━━\n\nTested On\n\nUbuntu 22.04\nNode.js v18.19.1\n\n━━━━━━━━━━━━━━━━━━━━━━\n\nCWE\n\nCWE-78 — Improper Neutralization of Special Elements used in an OS Command\n\n━━━━━━━━━━━━━━━━━━━━━━","published":"2026-06-12T20:37:00.522Z","modified":"2026-08-12T03:51:12.855671018Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H"},"epss":{"score":0.00428,"percentile":0.35684,"asOf":"2026-08-15"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@apostrophecms/cli","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42853.json"},{"type":"ADVISORY","url":"https://github.com/apostrophecms/apostrophe/security/advisories/GHSA-hcwq-x9fw-8cfq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42853"},{"type":"PACKAGE","url":"https://github.com/apostrophecms/apostrophe"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:12.855671018Z"}}