Command Injection Vulnerability in ApostropheCMS Node.js Package
CVE-2026-42853

6.5MEDIUM

Key Information:

Vendor
CVE Published:
12 June 2026

What is CVE-2026-42853?

ApostropheCMS, an open-source Node.js content management system, has a command injection vulnerability in its @apostrophecms/cli package versions up to and including 3.6.0. This occurs within the apos create command where user-supplied input from the password prompt is directly embedded into a shell command without appropriate sanitization or escaping. Consequently, this vulnerability permits an attacker to execute arbitrary commands on the host system. Currently, there are no known patched versions available.

Affected Version(s)

@apostrophecms/cli <= 3.6.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.