CVE-2026-53609 - Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass
CVE ID :CVE-2026-53609 Published : June 12, 2026, 10:16 p.m. | 51 minutes ago Description :ApostropheCMS is an open-source Node.js content management system. In versions up to and including 4.30.0, `apos.util.set()` traverses dot-notation paths without sanitizing `__proto__`, allowing an...