CVE-2026-32731Disclosure(apostrophecms / import-export)

LOWCVSS 9.9 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch apostrophecms import-export systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

ApostropheCMS is an open-source content management framework. Prior to version 3.5.3 of `@apostrophecms/import-export`, The `extract()` function in `gzip.js` constructs file-write paths using `fs.createWriteStream(path.join(exportPath, header.name))`. `path.join()` does not resolve or sanitise traversal segments such as `../`. It concatenates them as-is, meaning a tar entry named `../../evil.js` resolves to a path outside the intended extraction directory. No canonical-path check is performed before the write stream is opened. This is a textbook Zip Slip vulnerability. Any user who has been granted the Global Content Modify permission — a role routinely assigned to content editors and site managers — can upload a crafted `.tar.gz` file through the standard CMS import UI and write attacker-controlled content to any path the Node.js process can reach on the host filesystem. Version 3.5.3 of `@apostrophecms/import-export` fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • import-export

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-03-18); latest day: 2
  • 5 total mentions across 2 days

Affected systems

Products
import-export

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-03-18: 3Mentions · 2026-03-19: 2Patch / Workaround · 2026-03-18: 1Technical Details · 2026-03-18: 303-1803-19
Signal classification3 categories
Disclosure
360.0%
Patch
120.0%
General
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-183
Disclosure2Patch1
2026-03-192
Disclosure1General1
Full discourse5 posts
  • Er3n@0xEr3n
    General

    First cve done : CVE-2026-32731 This is only the beginning… many more to come.

    Post summary

    A brief note announcing the first CVE, CAPTURING no other actionable or technical information.

    2005082
    103 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32731 ApostropheCMS is an open-source content management framework. Prior to version 3.5.3 of `@apostrophecms/import-export`, The `extract()` function in `gzip.js` construc… https://www.cve.org/CVERecord?id=CVE-2026-32731

    Post summary

    The text provides a brief reference to CVE‑2026‑32731 in ApostropheCMS, noting a specific function in a pre‑3.5.3 module, but offers no detailed technical information, exploit details, or mitigation advice.

    00000129
    56.7K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-32731: CRITICAL] Vulnerability in ApostropheCMS prior to v3.5.3 allows content editors to exploit Zip Slip flaw by uploading malicious files. Update to v3.5.3 to fix the issue.#cve,CVE-2026-32731,#cybersecurity https://cvefind.com/CVE-2026-32731

    Post summary

    ApostropheCMS users are warned of a critical Zip Slip vulnerability that allows uploaded malicious files, and an immediate patch to version 3.5.3 is recommended; no exploit code or active exploitation evidence is provided.

    0000062
    603 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-32731 - Critical ApostropheCMS is an open-source content management framework. Prior to version 3.5.3 of `@apostrophecms/import-export`, The `extract()` function in `gzip.js` constructs file-write paths u... https://www.thehackerwire.com/vulnerability/CVE-2026-32731/ https://t.co/sZehUYFlku

    Post summary

    The tweet announces CVE-2026-32731 as a critical vulnerability in ApostropheCMS's import‑export module, highlighting a file‑write path issue in gzip.js and linking to an external vulnerability article.

    0000039
    138 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-32731: ApostropheCMS has Arbitrary File... Content editors with low-privilege accounts can drop shells anywhere on the filesystem via malicious tar.gz uploads—cla... https://zerodaysignal.com/vulnerability/CVE-2026-32731 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces an arbitrary file write vulnerability (CVE‑2026‑32731) in ApostropheCMS, enabling low‑privilege users to upload malicious tar.gz files that drop shells anywhere on the filesystem.

    0000064
    155 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapostrophecmsimport-export-node.js-

Explore more