#NØØT_Security_Alerts
🚨 #ALERT — CISA ADDS CRITICAL STRAPI VULNERABILITY TO KEV; RESEARCHERS PREVIOUSLY DEMONSTRATED AN UNAUTHENTICATED RCE EXPLOIT CHAIN
October 8, 2026
DISCLOSED BY:
CISA / Strapi Security
PRODUCT:
Strapi — Open-Source Headless CMS
CVE:
CVE-2023-22894 — Sensitive information disclosure through private-field filtering.
RELATED EXPLOIT CHAIN:
CVE-2023-22621 — Server-side template injection leading to remote code execution.
SEVERITY:
Critical
ORIGINAL DISCLOSURE:
April 17, 2023
MATERIAL RISK UPDATE:
CISA added CVE-2023-22894 to its Known Exploited Vulnerabilities catalog on October 8, 2026.
This is a NEW KEV inclusion for a previously disclosed vulnerability, not a newly discovered zero-day.
AFFECTED VERSIONS:
CVE-2023-22894:
Strapi 3.2.1 through versions earlier than 4.8.0.
CVE-2023-22621:
Affected Strapi releases through 4.5.5.
Strapi 3.x is unsupported.
IMPACT:
CVE-2023-22894 allows attackers to abuse filtering behavior to expose private information, including sensitive account information and password-reset tokens.
Strapi confirmed that researchers demonstrated how the vulnerability could facilitate administrator-account takeover.
On installations also vulnerable to CVE-2023-22621, the attacker could potentially chain administrator takeover with malicious email-template modification to execute arbitrary server-side code.
Strapi confirmed a working laboratory proof of concept for the unauthenticated exploit chain affecting releases through 4.5.5.
EXPLOITATION STATUS:
KNOWN EXPLOITATION CONFIRMED — CISA KEV.
The October 8 inclusion confirms documented exploitation of CVE-2023-22894.
It does NOT establish that the complete two-CVE remote-code-execution chain has been observed in current real-world attacks.
No new threat-actor attribution or victim count was provided.
knownRansomwareCampaignUse:
Unknown — CISA.
Forensic triage:
Review Strapi HTTP access logs for suspicious filtering parameters involving:
email
password
reset_password_token
resetPasswordToken
Investigate repeated requests attempting to retrieve private user attributes.
Review suspicious administrator password resets, unexpected privileged sessions, and unauthorized account modifications.
For the related template-injection vulnerability, inspect unexpected PUT requests to:
/users-permissions/email-templates
Review modified templates for suspicious executable expressions.
A matching request is an investigation lead, not proof of successful compromise.
URGENT ACTION:
Identify vulnerable Strapi installations immediately.
Upgrade to a currently supported, security-maintained Strapi release.
Strapi originally fixed CVE-2023-22894 in version 4.8.0 and CVE-2023-22621 in version 4.5.6.
Migrate unsupported Strapi 3.x deployments.
Restrict unnecessary public API exposure.
Investigate suspicious administrator password resets and rotate exposed credentials when compromise is established.
Preserve application logs and database evidence before remediation.
SOURCE:
https://strapi.io/blog/security-disclosure-of-vulnerabilities-cve
CISA:
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2023-22894
BACKUP:
https://raw.githubusercontent.com/cisagov/kev-data/develop/known_exploited_vulnerabilities.json
CONFIDENCE:
VERY HIGH — CISA’s October 8 catalog update confirms known exploitation. Strapi’s first-party security disclosure documents the affected releases, information-disclosure mechanism, demonstrated RCE chain, forensic indicators, and fixes.
Current attack scale and exploitation of the complete RCE chain remain unverified.
#CyberSecurity #ThreatIntel #Strapi #RCE #CISA #KEV #ActiveExploitation #WebSecurity #NØØT