MEDIUMnpm

@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header

@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header

CVE-2026-53607Published 5 days agoUpdated 5 days agoSource: OSV

Affected packages

  • apostrophe

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
0.23%
EPSS percentile
13.4%

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 13%.

@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header | HackTribune