highVulnerability

CVE-2026-71553

The vulnerability is a single-request persistent DoS by submitting e.g. "PATCH /api/v1/article/<id>" with a valid editor session and body of {"toString.call":"x"}, overwriting the global toString function with value x. Fabian

Properties

ghsa_id
GHSA-vmg4-6gfg-83qx
severity
high
summary
ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS
cve_id
CVE-2026-71553
is_ghsa_only
false
ghsa_published
2026-09-02T15:12:41Z
source_url
https://github.com/advisories/GHSA-vmg4-6gfg-83qx
ghsa_updated
2026-09-02T15:12:42Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]npm/apostrophe

AFFECTS (1)

[Software]npm/apostrophe

HAS_WEAKNESS (1)

[Weakness]Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-71553 — Ninja Signal Threat Intelligence | Ninja Signal