Denial of Service Vulnerability in ApostropheCMS by Apostrophe
CVE-2026-71553
7.1HIGH
What is CVE-2026-71553?
ApostropheCMS, an open-source Node.js content management system, is susceptible to a denial of service vulnerability found in versions 4.32.0 and earlier. The vulnerability occurs in the PATCH /api/v1/article/:id endpoint, where it improperly handles the inherited path to 'toString.call'. This flaw allows an authenticated editor to manipulate the shared 'Object.prototype.toString' function's call property. As a result, this can lead to a persistent process-wide denial of service that necessitates a server restart to recover functionality. It is essential for users of ApostropheCMS to review their installations and address this vulnerability to maintain system integrity.
Affected Version(s)
apostrophe <= 4.32.0
