THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-6h5j-32cf-4253 (critical) — Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass

[GHSA] GHSA-6h5j-32cf-4253 (critical) — Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass

medgithub_advisoriesPublished 2026-07-31

GHSA-6h5j-32cf-4253 Severity: critical CVE: CVE-2026-53609

Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass

<img width="1919" height="1046" alt="proto" src="https://github.com/user-attachments/assets/c5c69718-6448-448d-b64b-e3db41ab6ff6" />

## Summary

`apos.util.set()` traverses dot-notation paths without saniti

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-6h5j-32cf-4253