THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-wr5r-wqp2-x4fh (medium) — ApostropheCMS: Missing destination-parent authorization in page `move()` allows a low-privileged editor to move and re-rank pages inside a restricted subtree

[GHSA] GHSA-wr5r-wqp2-x4fh (medium) — ApostropheCMS: Missing destination-parent authorization in page `move()` allows a low-privileged editor to move and re-rank pages inside a restricted subtree

highgithub_advisoriesPublished 2026-09-03

GHSA-wr5r-wqp2-x4fh Severity: medium CVE: CVE-2026-63669

ApostropheCMS: Missing destination-parent authorization in page `move()` allows a low-privileged editor to move and re-rank pages inside a restricted subtree

## Summary ApostropheCMS enforces per-type authorization on pages: a page type may declare `editRole` / `publishRole` (and the core `@apostrophecms/archive-page` does), so a project c

Indicators of compromise

Original source: https://github.com/advisories/GHSA-wr5r-wqp2-x4fh