UNKNOWN npm

ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS

GHSA-vmg4-6gfg-83qx · CVE-2026-71553

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

The vulnerability is a single-request persistent DoS by submitting e.g.
"PATCH /api/v1/article/" with a valid editor session and body of
{"toString.call":"x"}, overwriting the global toString function with
value x.

Fabian

Ready to move

Start Securing

Free, no credit card | First findings in minutes