THREAT OPS › Threat News › [GHSA] GHSA-6h5j-32cf-4253 (critical) — Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass
[GHSA] GHSA-6h5j-32cf-4253 (critical) — Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass
GHSA-6h5j-32cf-4253 Severity: critical CVE: CVE-2026-53609
Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass
<img width="1919" height="1046" alt="proto" src="https://github.com/user-attachments/assets/c5c69718-6448-448d-b64b-e3db41ab6ff6" />
## Summary
`apos.util.set()` traverses dot-notation paths without saniti
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2026-53609cve
Original source: https://github.com/advisories/GHSA-6h5j-32cf-4253