{"api_version":"v1","generated_at":"2026-10-07T20:10:00+00:00","product":{"cve_count":2,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-apostrophe-apostrophe-9d9338adc856","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/apostrophe","name":"Apostrophe","next_cursor":null,"observations":[{"affected":"unspecified \u2264 3.3.1; 2.63.0 < unspecified","affected_versions_present":true,"cve_id":"CVE-2021-25979","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-25979","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-30T15:52:36.538Z","patch_url":"https://github.com/apostrophecms/apostrophe/commit/c211b211f9f4303a77a307cf41aac9b4ef8d2c7c","primary_source":"","published":"2021-11-08T14:20:11.000Z"},{"affected":"unspecified \u2264 3.3.1; 2.63.0 < unspecified","affected_versions_present":true,"cve_id":"CVE-2021-25978","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-25978","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-30T15:52:43.284Z","patch_url":"https://github.com/apostrophecms/apostrophe/commit/c8b94ee9c79468f1ce28e31966cb0e0839165e59","primary_source":"","published":"2021-11-07T17:15:10.000Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"Apostrophe"}}
