CVE-2026-71553Disclosure

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

ApostropheCMS is an open-source Node.js content management system. In 4.32.0 and earlier, PATCH /api/v1/article/:id accepts the inherited path toString.call and passes it through the utility module to apos.util.set() and apos.util.get(), allowing an authenticated editor to overwrite the shared Object.prototype.toString function's call property and cause a persistent process-wide denial of service until restart.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1321

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-08-17); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-17: 1Mentions · 2026-09-03: 1Patch / Workaround · 2026-08-17: 1Technical Details · 2026-09-03: 108-1709-03
Signal classification1 categories
Disclosure
2100.0%
Referenced assets3 URLs
Full discourse2 posts
  • DailyCVE@dailycve
    Disclosure

    🔴 ApostropheCMS, 2nd-order Prototype Pollution, #CVE-2026-71553 (High) -DC-Sep2026-2097 https://dailycve.com/apostrophecms-2nd-order-prototype-pollution-cve-2026-71553-high-dc-sep2026-2097/

    Post summary

    The tweet announces CVE-2026-71553 for ApostropheCMS as a high‑severity 2nd‑order prototype pollution vulnerability, but provides no PoC, exploit, patch, or active exploitation details.

    0000047
    233 followersView on X
  • MalwareObserver@MalwareObserver
    Disclosure

    🐛 VULNERABILITIES CVE Notify: 🚨 [CVE-2026-71553](https://github.com/apostrophecms/apostrophe/commit/5a3746aaed49761e171c2cbfe7932... https://github.com/apostrophecms/apostrophe/commit/5a3746aaed49761e171c2cbfe793267c959829fd #Vulnerability #CVE #ZeroDay

    Post summary

    The tweet announces CVE‑2026‑71553 as a potential zero‑day vulnerability and links to a GitHub commit, suggesting a patch was added, but it contains no exploit details, active use evidence, or technical specifics.

    0000026
    27 followersView on X

Explore more