Executive brief
The ApostropheCMS command-line tool, used by developers to manage website projects, contains a security flaw that allows for unauthorized command execution. If a developer is tricked into entering a specially crafted password during project creation, an attacker could execute malicious code on the developer's computer. This could lead to the theft of sensitive files, credential exposure, or full system compromise depending on the user's permissions.
Technical details
A command injection vulnerability exists in @apostrophecms/cli within the 'apos create' command (specifically in lib/commands/create.js). The application uses an interactive prompt to collect a password and embeds the resulting string directly into a shell command via the exec() function without sanitization or escaping. An attacker can use shell metacharacters (e.g., ;, &&, $()) in the password field to break out of the intended command and execute arbitrary OS commands with the privileges of the CLI user. While exploitation requires local interaction, it can be facilitated through social engineering or malicious documentation. As of the advisory date, no patched version is specified, but the recommended fix is to migrate from exec() to execFile() or execFileSync() to handle arguments safely.
Affected products
- ApostropheCMS @apostrophecms/cli <= 3.6.0
Timeline
- 2026-05-14: advisory: GitHub Advisory published
- 2026-06-12: disclosed: NVD publication
References
- https://api.github.com/users/VadlaReddySai
- https://github.com/VadlaReddySai
- https://api.github.com/users/VadlaReddySai/gists%7B/gist_id%7D
- https://api.github.com/users/VadlaReddySai/repos
- https://avatars.githubusercontent.com/u/146691360?v=4
- https://api.github.com/users/VadlaReddySai/events%7B/privacy%7D