A vulnerability labeled as critical has been found in Apostrophe up to 4.32.0. The affected element is the function apos.util.set/apos.util.get of the file /api/v1/article/:id of the component Utility Module. Executing a manipulation can lead to improperly controlled modification of object prototype attributes.

This vulnerability appears as CVE-2026-71553. The attack may be performed from remote. There is no available exploit.