Please help us keep all ApostropheCMS projects safe. If you become aware of a security vulnerability in ApostropheCMS or any official modules, please contact us via email at security@apostrophecms.com.
Security: apostrophecms/apostrophe
Security
SECURITY.md
-
nonTextTags discard region ends early on an implied close, letting <noscript> content renderGHSA-x3q4-9hxx-gx8m published
Oct 2, 2026 by boutellLow -
Host header controls server-side image fetch origin in @apostrophecms/ai-helper, enabling authenticated SSRFGHSA-527g-ff96-x6wj published
Oct 2, 2026 by boutellModerate -
Authenticated projection-exclusion prototype-member deletion in @apostrophecms/db-connect causes process-wide denial of serviceGHSA-j5rq-xfvr-p969 published
Oct 2, 2026 by boutellHigh -
Same-parent page reorder in @apostrophecms/page move() re-ranks a restricted parent's children without create authorizationGHSA-2jrp-qc93-h2j8 published
Oct 2, 2026 by boutellModerate -
CAPTCHA response token not URL-encodedGHSA-44qr-rrjg-2cqq published
Oct 2, 2026 by boutellModerate -
Cross-domain session token in URL confers session takeoverGHSA-hhvr-8m24-qqr3 published
Oct 2, 2026 by boutellModerate -
Unauthenticated unbounded multipart upload → disk-exhaustion DoSGHSA-89mh-mm8c-mv7f published
Oct 2, 2026 by boutellModerate -
Page REST API authorization bypassGHSA-2j32-q6rx-h844 published
Oct 2, 2026 by boutellModerate -
:_id/locales REST route omits the public-API authorization gate its sibling read routes enforce (unauthenticated doc-existence + locale metadata disclosure)GHSA-gqh3-7856-rjjg published
Oct 2, 2026 by boutellModerate -
Unauthenticated CSV import requests leave rejected uploads in the system temporary directoryGHSA-qhcq-9pm2-c9w9 published
Oct 2, 2026 by boutellHigh
Learn more about advisories related to apostrophecms/apostrophe in the GitHub Advisory Database