highVulnerability
CVE-2026-71553
The vulnerability is a single-request persistent DoS by submitting e.g. "PATCH /api/v1/article/<id>" with a valid editor session and body of {"toString.call":"x"}, overwriting the global toString function with value x. Fabian
Properties
- ghsa_id
- GHSA-vmg4-6gfg-83qx
- severity
- high
- summary
- ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS
- cve_id
- CVE-2026-71553
- is_ghsa_only
- false
- ghsa_published
- 2026-09-02T15:12:41Z
- source_url
- https://github.com/advisories/GHSA-vmg4-6gfg-83qx
- ghsa_updated
- 2026-09-02T15:12:42Z
Related Entities (4)
VULNERABLE_TO (1)
←[Software]npm/apostrophe
AFFECTS (1)
→[Software]npm/apostrophe
HAS_WEAKNESS (1)
→[Weakness]Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
REPORTED_BY (1)
→[Source]GitHub Advisory Database
Explore deeper with Ninja Signal's threat intelligence graph