Skip to content

ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal

Moderate severity GitHub Reviewed Published Aug 12, 2026 in apostrophecms/apostrophe • Updated Sep 2, 2026

Package

npm @apostrophecms/import-export (npm)

Affected versions

<= 3.6.1

Patched versions

3.6.2

Description

Summary

The @apostrophecms/import-export module reconstructs the on-disk source path of every imported attachment from JSON metadata contained in the uploaded archive.

The archive carries an aposAttachments.json file whose name and extension fields are concatenated into a filesystem path with no traversal check. The zip-slip guard that the module applies during tar extraction validates tar entry names only and does not cover this second path, which is built after extraction.

The file at the resulting path is read and copied into the public uploads directory, then served over HTTP without authentication. A ../ sequence in name makes the module read a file outside the extraction directory and publish it at an anonymous URL.

Result: an authenticated contributor reads any file on the host whose name ends in an allowlisted extension (other users' uploaded documents, text or CSV dumps, PDFs) by importing a crafted archive and fetching the planted attachment anonymously.

Affected

apostrophecms/apostrophe with the @apostrophecms/import-export module installed and registered. Module version 3.6.1 (current latest), tested against Apostrophe 4.31.0 (monorepo HEAD 4d478d9). Requires an account with the contributor role or higher; guest and anonymous requests are rejected. The module is not part of the default starter kit, so sites that never installed it are not affected. Files whose real name lacks an accepted file-group extension are not reachable.

Root cause

The import parser builds each attachment's source path by concatenating attacker-controlled JSON fields: lib/formats/gzip.js:46 sets file.path = path.join(attachmentFilesPath, ${attachment._id}-${attachment.name}.${attachment.extension}) from the aposAttachments.json entries in the uploaded archive. That path flows unchanged through lib/methods/import.js:832 (insertAttachments) into lib/methods/import.js:1074 (attachment.insert), where uploadfs copies the referenced file into the public uploads directory served by express.static. The archive's only traversal guard, lib/formats/gzip.js:143 (if (name.includes('../'))), validates tar entry names during extraction and never inspects the name/extension values used to construct the read path, so a name of ../../../../../../tmp/secret escapes attachmentFilesPath. Reaching the sink requires only an authenticated session (lib/methods/import.js:71), view permission on the target type (lib/methods/index.js:54), and the upload-attachment permission enforced at modules/@apostrophecms/attachment/index.js:442, which the built-in contributor role holds. The trailing .${extension} is appended and checked against the file-group allowlist in modules/@apostrophecms/attachment/index.js (getFileGroup), so the target file's real name must end in an accepted extension (txt, csv, pdf, xls, doc, svg, and similar).

Reproduction

Apostrophe 4.31.0 starter-kit-essentials, MongoDB, default roles, @apostrophecms/import-export 3.6.1 installed, local uploadfs backend.

  1. Place a secret file outside the upload tree with an allowlisted extension.
$ cat /tmp/apos_victim_secret.txt
TOP-SECRET DB DUMP
DB_PASSWORD=Pr0d-Secret-9981
API_KEY=sk_live_victim_abcdef
  1. Build a gzip archive whose aposAttachments.json points the attachment name at that file through traversal (aposDocs.json is []).
[{"_id":"evilatt0001","name":"../../../../../../../../../../../../tmp/apos_victim_secret","extension":"txt","title":"loot","docIds":[],"crops":[]}]
  1. As a contributor, import the archive through the module's import action (POST /api/v1/@apostrophecms/<type>/import-export-import), then fetch the created attachment with no session.
$ curl -i http://localhost:3500/uploads/attachments/evilatt0001-apos-victim-secret.txt
HTTP/1.1 200 OK
Content-Type: text/plain; charset=UTF-8

TOP-SECRET DB DUMP
DB_PASSWORD=Pr0d-Secret-9981
API_KEY=sk_live_victim_abcdef

Live-verified: a contributor-driven import reads /tmp/apos_victim_secret.txt (outside the extraction directory) and serves it at an anonymous URL; the same import run as a guest is rejected at the upload-attachment check (modules/@apostrophecms/attachment/index.js:442).

Impact

  • Read of arbitrary host files whose real name ends in an allowlisted extension (txt, csv, pdf, xls, doc, svg, and similar).
  • Disclosure of other users' uploaded documents and any allowlisted-extension file readable by the Node process.
  • The exfiltration target is copied to a public, unauthenticated URL.
  • Triggered by the contributor role in a single import, no admin interaction.

Credit

Jan Kahmen, turingpoint (jan@turingpoint.de)

References

@boutell boutell published to apostrophecms/apostrophe Aug 12, 2026
Published by the National Vulnerability Database Aug 17, 2026
Published to the GitHub Advisory Database Sep 2, 2026
Reviewed Sep 2, 2026
Last updated Sep 2, 2026

Severity

Moderate

CVSS overall score

This score calculates overall vulnerability severity from 0 to 10 and is based on the Common Vulnerability Scoring System (CVSS).
/ 10

CVSS v3 base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

CVSS v3 base metrics

Attack vector: More severe the more the remote (logically and physically) an attacker can be in order to exploit the vulnerability.
Attack complexity: More severe for the least complex attacks.
Privileges required: More severe if no privileges are required.
User interaction: More severe when no user interaction is required.
Scope: More severe when a scope change occurs, e.g. one vulnerable component impacts resources in components beyond its security scope.
Confidentiality: More severe when loss of data confidentiality is highest, measuring the level of data access available to an unauthorized user.
Integrity: More severe when loss of data integrity is the highest, measuring the consequence of data modification possible by an unauthorized user.
Availability: More severe when the loss of impacted component availability is highest.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS score

Exploit Prediction Scoring System (EPSS)

This score estimates the probability of this vulnerability being exploited within the next 30 days. Data provided by FIRST.
(27th percentile)

Weaknesses

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory. Learn more on MITRE.

CVE ID

CVE-2026-63667

GHSA ID

GHSA-79qf-vqgc-7xx3

Credits

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.