SCA: security update for apostrophe (GHSA-5f64-7vfc-rcx6)

high Tenable Cloud Security Plugin ID 446781

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- ApostropheCMS is an open-source Node.js content management system. Version 4.29.0 has a stored cross-site
scripting vulnerability in the image widget functionality. A user with the Editor role can configure an
image widget link to use a javascript: URL payload. Because editors have permission to publish pages, the
malicious widget can be published to the live site. When another user, including an administrator or
public visitor, clicks the affected image/link, arbitrary JavaScript executes in the victim’s browser. As
of time of publication, no known patched versions are available. (CVE-2026-45011)

Solution

There is no known solution at this time.

See Also

https://github.com/advisories/GHSA-5f64-7vfc-rcx6

Plugin Details

Severity: High

ID: 446781

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 8/31/2026

Updated: 8/31/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.66

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 8.5

Temporal Score: 6.3

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:N

CVSS Score Source: CVE-2026-45011

CVSS v3

Risk Factor: High

Base Score: 7.3

Temporal Score: 6.4

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/14/2026

Vulnerability Publication Date: 5/14/2026

Reference Information

CVE: CVE-2026-45011