NPM · JULY 2026 · EARLY WARNING

@apostrophecms/file npm Package Vulnerability: Early Warning

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
GHSA-34PJ-2622-JVXQSeverity: HIGH

An early warning has been issued regarding a potential unauthenticated SSRF vulnerability in the @apostrophecms/file npm package when the prettyUrls feature is enabled. This vulnerability could allow an attacker to issue outbound HTTP requests against any host reachable on the private network.

What happened

Reportedly, the @apostrophecms/file npm package is vulnerable to unauthenticated Server-Side Request Forgery (SSRF) via the Host header when the prettyUrls feature is enabled. This vulnerability, tracked under GHSA-34PJ-2622-JVXQ, appears to allow an attacker to pivot the apostrophe process to issue outbound HTTP requests against any host it can reach on the private network.

The vulnerability is under investigation and has been reported to affect versions of @apostrophecms/file up to and including 4.30.0. To assess your exposure, check if your project utilizes the @apostrophecms/file package with the prettyUrls feature enabled.

As a recommended action, it is advised to disable the prettyUrls feature in @apostrophecms/file or upgrade to a version where this issue is fixed once available. For more detailed information, consult the primary sources linked in the summary.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If @apostrophecms/file is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats