THREAT OPS › Threat News › [GHSA] GHSA-79qf-vqgc-7xx3 (medium) — ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal
[GHSA] GHSA-79qf-vqgc-7xx3 (medium) — ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal
GHSA-79qf-vqgc-7xx3 Severity: medium CVE: CVE-2026-63667
ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal
## Summary
The `@apostrophecms/import-export` module reconstructs the on-disk source path of every imported attachment from JSON metadata contained in the uploaded archive.
The archive carries an `aposAttachments.json` file whose `name` and `extension` fi
Indicators of compromise
- CVE-2026-63667cve
- https://www.turingpoint.deurl
- jan@turingpoint.deemail
Original source: https://github.com/advisories/GHSA-79qf-vqgc-7xx3