{"id":"CVE-2026-71553","aliases":["GHSA-vmg4-6gfg-83qx"],"url":"https://o3.security/vulnerability/CVE-2026-71553","summary":"ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS","details":"ApostropheCMS is an open-source Node.js content management system. In 4.32.0 and earlier, PATCH /api/v1/article/:id accepts the inherited path toString.call and passes it through the utility module to apos.util.set() and apos.util.get(), allowing an authenticated editor to overwrite the shared Object.prototype.toString function's call property and cause a persistent process-wide denial of service until restart.","published":"2026-08-17T20:03:37.883Z","modified":"2026-09-11T03:30:37.984270106Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"apostrophe","fixedVersion":null}],"fix":{"url":"https://github.com/apostrophecms/apostrophe/commit/5a3746aaed49761e171c2cbfe793267c959829fd","label":"apostrophecms/apostrophe@5a3746a"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/71xxx/CVE-2026-71553.json"},{"type":"ADVISORY","url":"https://github.com/apostrophecms/apostrophe/security/advisories/GHSA-vmg4-6gfg-83qx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-71553"},{"type":"FIX","url":"https://github.com/apostrophecms/apostrophe/commit/5a3746aaed49761e171c2cbfe793267c959829fd"},{"type":"PACKAGE","url":"https://github.com/apostrophecms/apostrophe"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-11T03:30:37.984270106Z"}}