<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T18:28:58.720360+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-327357</id>
    <title>EUVD-2026-327357</title>
    <updated>2026-10-05T18:28:58.771652+00:00</updated>
    <content>EUVD-2026-327357</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-327357"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-53609</id>
    <title>fkie_cve-2026-53609</title>
    <updated>2026-10-05T18:28:58.771694+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ApostropheCMS is an open-source Node.js content management system. In versions up to and including 4.30.0, `apos.util.set()` traverses dot-notation paths without sanitizing `__proto__`, allowing an authenticated editor to write arbitrary values to `Object.prototype` via the `$pullAll` patch operator. A confirmed gadget in `publicApiCheck()` causes this to bypass authorization on all piece-type REST API endpoints for every subsequent unauthenticated request, for the lifetime of the Node.js process. As of time of publication, no known patched versions are available.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-53609"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6h5j-32cf-4253</id>
    <title>GHSA-6h5j-32cf-4253 — Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authoriz…</title>
    <updated>2026-10-05T18:28:58.771731+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: apostrophe</p>
<p>&lt;img width="1919" height="1046" alt="proto" src="https://github.com/user-attachments/assets/c5c69718-6448-448d-b64b-e3db41ab6ff6" /&gt;</p>
<p>## Summary</p>
<p>`apos.util.set()` traverses dot-notation paths without sanitizing `__proto__`, allowing an authenticated editor to write arbitrary values to `Object.prototype` via the `$pullAll` patch operator.</p>
<p>A confirmed gadget in `publicApiCheck()` causes this to bypass authorization on all piece-type REST API endpoints for every subsequent unauthenticated request, for the lifetime of the Node.js process.</p>
<p>---</p>
<p>## Details</p>
<p>### Root Cause — `apos.util.set()` (`modules/@apostrophecms/util/index.js` ~line 800)</p>
<p>The function splits a dot-notation path and traverses properties without rejecting `__proto__`, `constructor`, or `prototype`:</p>
<p>```js
set(o, path, v) {
  path = path.split('.');
  for (i = 0; i &lt; path.length - 1; i++) {
    o = o[path[i]];   // when path[i] === '__proto__', o becomes Object.prototype
  }
  o[path[i]] = v;     // mutates Object.prototype
}
```</p>
<p>### Source — `implementPatchOperators()` (`modules/@apostrophecms/schema/index.js` ~line 1737)</p>
<p>User-controlled keys from the `$pullAll` operator are passed directly to `apos.util.set()`:</p>
<p>```js
_.each(patch.$pullAll, function(val, key) {
  cloneOriginalBase(key);               // uses _.has (hasOwnProperty)
  self.apos.util.set(patch, key, ...);  // key is fully attacker-controlled
});
```</p>
<p>`cloneOriginalBase()` does not sanitize `__proto__` because `_.has()` performs an own-propert…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6h5j-32cf-4253"/>
  </entry>
</feed>
