CVE-2026-35569: Stored XSS in SEO Fields Leads to Authenticated API Data Exposure in ApostropheCMS
(updated )
A stored cross-site scripting (XSS) vulnerability exists in SEO-related fields (SEO Title and Meta Description) in ApostropheCMS.
Improper neutralization of user-controlled input in SEO-related fields allows injection of arbitrary JavaScript into HTML contexts, resulting in stored cross-site scripting (XSS). This can be leveraged to perform authenticated API requests and exfiltrate sensitive data, resulting in a compromise of application confidentiality.
References
- github.com/Chittu13/cve-research/tree/main/CVE-2026-35569
- github.com/advisories/GHSA-855c-r2vq-c292
- github.com/apostrophecms/apostrophe
- github.com/apostrophecms/apostrophe/commit/0e57dd07a56ae1ba1e3af646ba026db4d0ab5bb3
- github.com/apostrophecms/apostrophe/security/advisories/GHSA-855c-r2vq-c292
- nvd.nist.gov/vuln/detail/CVE-2026-35569
Code Behaviors & Features
Detect and mitigate CVE-2026-35569 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →