CVE-2026-53609
ApostropheCMS `__proto__` Prototype Pollution Leading to Authentication Bypass
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
An authenticated editor can exploit a flaw in ApostropheCMS, a Node.js content management system, to bypass authorization checks. This prototype pollution vulnerability could allow unauthenticated users to access sensitive content or features for the duration of the application process, impacting internet-facing conten