
First cve done : CVE-2026-32731 This is only the beginning… many more to come.
Post summary
A brief note announcing the first CVE, CAPTURING no other actionable or technical information.
Signal is active with 2 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
ApostropheCMS is an open-source content management framework. Prior to version 3.5.3 of `@apostrophecms/import-export`, The `extract()` function in `gzip.js` constructs file-write paths using `fs.createWriteStream(path.join(exportPath, header.name))`. `path.join()` does not resolve or sanitise traversal segments such as `../`. It concatenates them as-is, meaning a tar entry named `../../evil.js` resolves to a path outside the intended extraction directory. No canonical-path check is performed before the write stream is opened. This is a textbook Zip Slip vulnerability. Any user who has been granted the Global Content Modify permission — a role routinely assigned to content editors and site managers — can upload a crafted `.tar.gz` file through the standard CMS import UI and write attacker-controlled content to any path the Node.js process can reach on the host filesystem. Version 3.5.3 of `@apostrophecms/import-export` fixes the issue.
Priority
LOW
Exploitation
NONE
PoC
YES
Patch
AVAILABLE
Momentum
STABLE
If you run products in this scope, you should treat this CVE as relevant to your environment.
| Date | Total | Labels |
|---|
| 2026-03-18 | 3 | Disclosure2Patch1 |
| 2026-03-19 | 2 | Disclosure1General1 |

First cve done : CVE-2026-32731 This is only the beginning… many more to come.
Post summary
A brief note announcing the first CVE, CAPTURING no other actionable or technical information.

CVE-2026-32731 ApostropheCMS is an open-source content management framework. Prior to version 3.5.3 of `@apostrophecms/import-export`, The `extract()` function in `gzip.js` construc… https://www.cve.org/CVERecord?id=CVE-2026-32731
Post summary
The text provides a brief reference to CVE‑2026‑32731 in ApostropheCMS, noting a specific function in a pre‑3.5.3 module, but offers no detailed technical information, exploit details, or mitigation advice.

[CVE-2026-32731: CRITICAL] Vulnerability in ApostropheCMS prior to v3.5.3 allows content editors to exploit Zip Slip flaw by uploading malicious files. Update to v3.5.3 to fix the issue.#cve,CVE-2026-32731,#cybersecurity https://cvefind.com/CVE-2026-32731
Post summary
ApostropheCMS users are warned of a critical Zip Slip vulnerability that allows uploaded malicious files, and an immediate patch to version 3.5.3 is recommended; no exploit code or active exploitation evidence is provided.

🔴 CVE-2026-32731 - Critical ApostropheCMS is an open-source content management framework. Prior to version 3.5.3 of `@apostrophecms/import-export`, The `extract()` function in `gzip.js` constructs file-write paths u... https://www.thehackerwire.com/vulnerability/CVE-2026-32731/ https://t.co/sZehUYFlku
Post summary
The tweet announces CVE-2026-32731 as a critical vulnerability in ApostropheCMS's import‑export module, highlighting a file‑write path issue in gzip.js and linking to an external vulnerability article.

🚨 CVE-2026-32731: ApostropheCMS has Arbitrary File... Content editors with low-privilege accounts can drop shells anywhere on the filesystem via malicious tar.gz uploads—cla... https://zerodaysignal.com/vulnerability/CVE-2026-32731 #netsec #vulnerability #CVE #sysadmin #zeroday
Post summary
The post announces an arbitrary file write vulnerability (CVE‑2026‑32731) in ApostropheCMS, enabling low‑privilege users to upload malicious tar.gz files that drop shells anywhere on the filesystem.
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | apostrophecms | import-export | - | node.js | - |