CVE-2026-53608: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in apostrophecms @apostrophecms/seo
ApostropheCMS is an open-source Node.js content management system. Versions up to and including 1.4.2 of the `@apostrophecms/seo` package injects the Google Analytics Tracking ID (`seoGoogleTrackingId`) and Google Tag Manager ID (`seoGoogleTagManager`) directly into `<script>` tag bodies using JavaScript template literals without any sanitization or validation. Any user with editor-level access (the default role for content managers) can set these fields to a malicious value, resulting in stored XSS that executes on every page for every visitor of the site. As of time of publication, no known patched versions are available.
AI Analysis
Technical Summary
The vulnerability in ApostropheCMS's @apostrophecms/seo package (up to version 1.4.2) arises from improper neutralization of input during web page generation (CWE-79). Specifically, the Google Analytics Tracking ID and Google Tag Manager ID fields are inserted directly into script tag bodies using JavaScript template literals without sanitization or validation. Since editor-level users can modify these fields, they can inject malicious scripts that result in stored XSS affecting all visitors. The CVSS 3.1 score is 8.7 (high severity) reflecting network attack vector, low attack complexity, required privileges at editor level, user interaction required, scope changed, and high impact on confidentiality and integrity. No patch or official remediation is currently available.
Potential Impact
Successful exploitation allows an attacker with editor-level access to inject malicious JavaScript that executes in the context of every visitor's browser. This compromises confidentiality and integrity of user data on the site. The vulnerability does not impact availability. The attack requires privileges and user interaction but can affect all site visitors once exploited.
Mitigation Recommendations
As of the publication date, no official patch or fix is available for this vulnerability. Users should restrict editor-level access to trusted personnel only and consider additional application-level input validation or sanitization as a temporary mitigation. Monitor vendor advisories for updates regarding patches or official remediation.
CVE-2026-53608: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in apostrophecms @apostrophecms/seo
Description
ApostropheCMS is an open-source Node.js content management system. Versions up to and including 1.4.2 of the `@apostrophecms/seo` package injects the Google Analytics Tracking ID (`seoGoogleTrackingId`) and Google Tag Manager ID (`seoGoogleTagManager`) directly into `<script>` tag bodies using JavaScript template literals without any sanitization or validation. Any user with editor-level access (the default role for content managers) can set these fields to a malicious value, resulting in stored XSS that executes on every page for every visitor of the site. As of time of publication, no known patched versions are available.
CVSS v3.1
Score 8.7high
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in ApostropheCMS's @apostrophecms/seo package (up to version 1.4.2) arises from improper neutralization of input during web page generation (CWE-79). Specifically, the Google Analytics Tracking ID and Google Tag Manager ID fields are inserted directly into script tag bodies using JavaScript template literals without sanitization or validation. Since editor-level users can modify these fields, they can inject malicious scripts that result in stored XSS affecting all visitors. The CVSS 3.1 score is 8.7 (high severity) reflecting network attack vector, low attack complexity, required privileges at editor level, user interaction required, scope changed, and high impact on confidentiality and integrity. No patch or official remediation is currently available.
Potential Impact
Successful exploitation allows an attacker with editor-level access to inject malicious JavaScript that executes in the context of every visitor's browser. This compromises confidentiality and integrity of user data on the site. The vulnerability does not impact availability. The attack requires privileges and user interaction but can affect all site visitors once exploited.
Mitigation Recommendations
As of the publication date, no official patch or fix is available for this vulnerability. Users should restrict editor-level access to trusted personnel only and consider additional application-level input validation or sanitization as a temporary mitigation. Monitor vendor advisories for updates regarding patches or official remediation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-09T19:39:52.404Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a2c7c93e617e2d834c6c823
Added to database: 06/12/2026, 21:39:31 UTC
Last enriched: 06/19/2026, 22:21:03 UTC
Last updated: 07/31/2026, 19:22:59 UTC
Views: 102
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.