{"id":"CVE-2026-71553","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-71553","summary":"ApostropheCMS is an open-source Node.js content management system. In 4.32.0 and earlier, PATCH /api/v1/article/:id accepts the inherited path toString.call and passes it through the…","details":"ApostropheCMS is an open-source Node.js content management system. In 4.32.0 and earlier, PATCH /api/v1/article/:id accepts the inherited path toString.call and passes it through the utility module to apos.util.set() and apos.util.get(), allowing an authenticated editor to overwrite the shared Object.prototype.toString function's call property and cause a persistent process-wide denial of service until restart.","published":"2026-08-17T20:16:46.073","modified":"2026-08-17T20:16:46.073","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/apostrophecms/apostrophe/commit/5a3746aaed49761e171c2cbfe793267c959829fd","label":"apostrophecms/apostrophe@5a3746a"},"references":[{"type":"WEB","url":"https://github.com/apostrophecms/apostrophe/commit/5a3746aaed49761e171c2cbfe793267c959829fd"},{"type":"WEB","url":"https://github.com/apostrophecms/apostrophe/security/advisories/GHSA-vmg4-6gfg-83qx"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-17T20:16:46.073"}}