CVE-2026-63667

ApostropheCMS is an open-source Node.js content management system. Prior to 3.6.2, the import-export module in packages/import-export/lib/formats/gzip.js constructs an attachment source path from the attacker-controlled _id, name, and extension fields in aposAttachments.json without ensuring that the resolved path remains under the extracted attachments directory, allowing an authenticated contributor to import a crafted archive, read a host file with an allowed extension, and publish the copied file at an unauthenticated uploads URL. This issue is fixed in version 3.6.2.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-17 20:16

Updated : 2026-09-09 21:11


NVD link : CVE-2026-63667

Mitre link : CVE-2026-63667

CVE.ORG link : CVE-2026-63667


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')