THREAT OPS › Threat News › [GHSA] GHSA-wr5r-wqp2-x4fh (medium) — ApostropheCMS: Missing destination-parent authorization in page `move()` allows a low-privileged editor to move and re-rank pages inside a restricted subtree
[GHSA] GHSA-wr5r-wqp2-x4fh (medium) — ApostropheCMS: Missing destination-parent authorization in page `move()` allows a low-privileged editor to move and re-rank pages inside a restricted subtree
GHSA-wr5r-wqp2-x4fh Severity: medium CVE: CVE-2026-63669
ApostropheCMS: Missing destination-parent authorization in page `move()` allows a low-privileged editor to move and re-rank pages inside a restricted subtree
## Summary ApostropheCMS enforces per-type authorization on pages: a page type may declare `editRole` / `publishRole` (and the core `@apostrophecms/archive-page` does), so a project c
Indicators of compromise
- 9f72bd229be07e537a2ae894f4527f2fe6bcd3bdsha1
- CVE-2026-63669cve
Original source: https://github.com/advisories/GHSA-wr5r-wqp2-x4fh