Command Injection Vulnerability in ApostropheCMS Node.js Package
CVE-2026-42853
6.5MEDIUM
What is CVE-2026-42853?
ApostropheCMS, an open-source Node.js content management system, has a command injection vulnerability in its @apostrophecms/cli package versions up to and including 3.6.0. This occurs within the apos create command where user-supplied input from the password prompt is directly embedded into a shell command without appropriate sanitization or escaping. Consequently, this vulnerability permits an attacker to execute arbitrary commands on the host system. Currently, there are no known patched versions available.
Affected Version(s)
@apostrophecms/cli <= 3.6.0
