CVE Explorer
CVE-2026-42853
ApostropheCMS is an open-source Node.js content management system. Versions of the @apostrophecms/cli package up to and including 3.6.0 contain a command injection vulnerability in the apos create command. User-supplied input from the password prompt is embedded directly into a shell command without proper sanitization or escaping. This allows execution of arbitrary commands on the host system. As of time of publication, no known patched versions are available.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"@apostrophecms/cli","vendor":"apostrophecms","versions":[{"status":"affected","version":"<= 3.6.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:06d6b1b335480f3eb46442bb341d3190148f1000a5a11a72f8cd1e5e2b9f7e2a · sha256:da28c577bbd3dc01… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:06d6b1b335480f3eb46442bb341d3190148f1000a5a11a72f8cd1e5e2b9f7e2a · sha256:da28c577bbd3dc01… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-78","description":"CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:06d6b1b335480f3eb46442bb341d3190148f1000a5a11a72f8cd1e5e2b9f7e2a · sha256:da28c577bbd3dc01… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"tags":["exploit"],"url":"https://github.com/apostrophecms/apostrophe/security/advisories/GHSA-hcwq-x9fw-8cfq"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:06d6b1b335480f3eb46442bb341d3190148f1000a5a11a72f8cd1e5e2b9f7e2a · sha256:da28c577bbd3dc01… · /containers/adp/0/references/0
{"name":"https://github.com/apostrophecms/apostrophe/security/advisories/GHSA-hcwq-x9fw-8cfq","tags":["x_refsource_CONFIRM"],"url":"https://github.com/apostrophecms/apostrophe/security/advisories/GHSA-hcwq-x9fw-8cfq"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:06d6b1b335480f3eb46442bb341d3190148f1000a5a11a72f8cd1e5e2b9f7e2a · sha256:da28c577bbd3dc01… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.