MEDIUM6.5npm
GHSA-79qf-vqgc-7xx3· CVE-2026-63667ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal
Modified: 9/2/2026
package
pkg:npm/%40apostrophecms/import-export
ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal
Modified: 9/2/2026
ApostropheCMS has Arbitrary File Write (Zip Slip / Path Traversal) in Import-Export Gzip Extraction
Modified: 3/18/2026