THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-79qf-vqgc-7xx3 (medium) — ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal

[GHSA] GHSA-79qf-vqgc-7xx3 (medium) — ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal

highgithub_advisoriesPublished 2026-09-02

GHSA-79qf-vqgc-7xx3 Severity: medium CVE: CVE-2026-63667

ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal

## Summary

The `@apostrophecms/import-export` module reconstructs the on-disk source path of every imported attachment from JSON metadata contained in the uploaded archive.

The archive carries an `aposAttachments.json` file whose `name` and `extension` fi

Indicators of compromise

Original source: https://github.com/advisories/GHSA-79qf-vqgc-7xx3