CVE-2023-22621Active Exploitation(strapi / strapi)

HIGHCVSS 7.2 · HIGH

Exploitation ongoing with high activity in latest observed window (4 mentions)

Immediate actions

  • Prioritize remediation for strapi strapi systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitrary code on the server. A remote attacker with access to the Strapi admin panel can inject a crafted payload that executes code on the server into an email template that bypasses the validation checks that should prevent code execution.

7.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • strapi

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • 9 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked at 4 mentions on most recent observed day (2026-10-09)
  • 9 total mentions across 4 days

Affected systems

Vendors
Products
strapi

Deep dive

Activity timeline9 mentions / 4d
01234Mentions · 2026-04-21: 1Mentions · 2026-08-17: 2Mentions · 2026-10-08: 2Mentions · 2026-10-09: 4PoC Mentioned / Linked · 2026-08-17: 1Exploit Tool / Code · 2026-08-17: 1Active Exploitation · 2026-04-21: 1Technical Details · 2026-04-21: 104-2108-1710-0810-09
Signal classification3 categories
Active Exploitation
133.3%
General
133.3%
PoC
133.3%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-04-211
Active Exploitation1
2026-08-172
General1PoC1
Full discourse9 posts
  • FOFA@fofabot

    ⚠️⚠️ CVE-2023-22894 (+ CVE-2023-22621): Actively exploited in the wild (CISA KEV 10/08) — cleartext storage in Strapi admin chains to unauthenticated remote code execution on self-hosted headless CMS instances. 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJzdHJhcGktSGVhZGxlc3MtQ01TIg== 🎯169k+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="strapi-Headless-CMS" 🔖Refer: https://www.cisa.gov/known-exploited-vulnerabilities-catalog #OSINT #FOFA #CyberSecurity #Vulnerability

    16136182.5K
    14.8K followersView on X
  • ExploitGrid@exploitgrid
    PoC

    [EXPLOIT] EGE-GH-MKUk78n [CRITICAL/PoC] Linked: CVE-2023-22621 CVE-2023-22621-POC 🔗 https://exploitgrid.net/exploits/383ee1d1-456e-400b-8cd0-c43309535103

    Post summary

    A PoC for CVE‑2023‑22621 is made publicly available via ExploitGrid, indicating an exploitable vulnerability with a ready‑to‑use proof of concept.

    1000022
    33 followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: EGE-GH-z2Wb7PG ( CVE-2026-72898 ) EGE-GH-UkSJfvx ( CVE-2026-73678 ) EGE-GH-MKUk78n ( CVE-2023-22621 ) EGE-GH-EjpQM0Q ( CVE-2025-3243, CVE-2025-32433 ) EGE-GH-seDm3r2 ( CVE-2025-55182 ) ..🧵👇

    Post summary

    The tweet simply lists several CVE identifiers without providing any additional technical details, proofs, patches, or exploitation claims.

    1000042
    33 followersView on X
  • ♫Why♥Not♪@Python_s_

    #NØØT_Security_Alerts 🚨 #ALERT — CISA CONFIRMS EXPLOITATION OF STRAPI VULNERABILITY LINKED TO ACCOUNT TAKEOVER AND REMOTE CODE EXECUTION CHAINS October 8, 2026 PRODUCT: Strapi Headless CMS CVE: CVE-2023-22894 IMPACT: Attackers can exploit vulnerable filtering functionality to expose sensitive user information, including password hashes and password-reset tokens. Strapi documented an unauthenticated account-takeover path under applicable conditions. When chained with CVE-2023-22621, vulnerable Strapi installations through version 4.5.5 can allow unauthenticated remote code execution. AFFECTED VERSIONS: Strapi 3.2.1 through versions before 4.8.0. EXPLOITATION STATUS: CONFIRMED KNOWN EXPLOITATION — CISA KEV. New KEV inclusion: October 8, 2026. The vendor-confirmed RCE chain is technically demonstrated; CISA’s listing does not establish that attackers achieved RCE in every observed intrusion. knownRansomwareCampaignUse: Unknown. URGENT ACTION: Upgrade to a supported, patched Strapi release. Review application logs for suspicious requests containing password, reset_password_token, or resetPasswordToken filtering parameters. Investigate unexpected password resets, administrator access, and email-template modifications. SOURCE: https://strapi.io/blog/security-disclosure-of-vulnerabilities-cve CISA: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2023-22894 BACKUP: https://raw.githubusercontent.com/cisagov/kev-data/develop/known_exploited_vulnerabilities.json CONFIDENCE: VERY HIGH — CISA confirms known exploitation. Strapi’s official security disclosure documents the information exposure, account-takeover mechanism, and conditional RCE chain. #CyberSecurity #ThreatIntel #Strapi #AccountTakeover #ActiveExploitation #CISA #KEV #NØØT

    0000050
    229 followersView on X
  • ♫Why♥Not♪@Python_s_

    #NØØT_Security_Alerts 🚨 #ALERT — CISA ADDS CRITICAL STRAPI VULNERABILITY TO KEV; RESEARCHERS PREVIOUSLY DEMONSTRATED AN UNAUTHENTICATED RCE EXPLOIT CHAIN October 8, 2026 DISCLOSED BY: CISA / Strapi Security PRODUCT: Strapi — Open-Source Headless CMS CVE: CVE-2023-22894 — Sensitive information disclosure through private-field filtering. RELATED EXPLOIT CHAIN: CVE-2023-22621 — Server-side template injection leading to remote code execution. SEVERITY: Critical ORIGINAL DISCLOSURE: April 17, 2023 MATERIAL RISK UPDATE: CISA added CVE-2023-22894 to its Known Exploited Vulnerabilities catalog on October 8, 2026. This is a NEW KEV inclusion for a previously disclosed vulnerability, not a newly discovered zero-day. AFFECTED VERSIONS: CVE-2023-22894: Strapi 3.2.1 through versions earlier than 4.8.0. CVE-2023-22621: Affected Strapi releases through 4.5.5. Strapi 3.x is unsupported. IMPACT: CVE-2023-22894 allows attackers to abuse filtering behavior to expose private information, including sensitive account information and password-reset tokens. Strapi confirmed that researchers demonstrated how the vulnerability could facilitate administrator-account takeover. On installations also vulnerable to CVE-2023-22621, the attacker could potentially chain administrator takeover with malicious email-template modification to execute arbitrary server-side code. Strapi confirmed a working laboratory proof of concept for the unauthenticated exploit chain affecting releases through 4.5.5. EXPLOITATION STATUS: KNOWN EXPLOITATION CONFIRMED — CISA KEV. The October 8 inclusion confirms documented exploitation of CVE-2023-22894. It does NOT establish that the complete two-CVE remote-code-execution chain has been observed in current real-world attacks. No new threat-actor attribution or victim count was provided. knownRansomwareCampaignUse: Unknown — CISA. Forensic triage: Review Strapi HTTP access logs for suspicious filtering parameters involving: email password reset_password_token resetPasswordToken Investigate repeated requests attempting to retrieve private user attributes. Review suspicious administrator password resets, unexpected privileged sessions, and unauthorized account modifications. For the related template-injection vulnerability, inspect unexpected PUT requests to: /users-permissions/email-templates Review modified templates for suspicious executable expressions. A matching request is an investigation lead, not proof of successful compromise. URGENT ACTION: Identify vulnerable Strapi installations immediately. Upgrade to a currently supported, security-maintained Strapi release. Strapi originally fixed CVE-2023-22894 in version 4.8.0 and CVE-2023-22621 in version 4.5.6. Migrate unsupported Strapi 3.x deployments. Restrict unnecessary public API exposure. Investigate suspicious administrator password resets and rotate exposed credentials when compromise is established. Preserve application logs and database evidence before remediation. SOURCE: https://strapi.io/blog/security-disclosure-of-vulnerabilities-cve CISA: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2023-22894 BACKUP: https://raw.githubusercontent.com/cisagov/kev-data/develop/known_exploited_vulnerabilities.json CONFIDENCE: VERY HIGH — CISA’s October 8 catalog update confirms known exploitation. Strapi’s first-party security disclosure documents the affected releases, information-disclosure mechanism, demonstrated RCE chain, forensic indicators, and fixes. Current attack scale and exploitation of the complete RCE chain remain unverified. #CyberSecurity #ThreatIntel #Strapi #RCE #CISA #KEV #ActiveExploitation #WebSecurity #NØØT

    0000082
    229 followersView on X
  • Samit Hota @HotaSamit

    Strapi CVE-2023-22894: Query Filter Secrets Leak Enables RCE Chaining Strapi CVE-2023-22894 exposes sensitive data via query filters, enabling attackers to chain it with CVE-2023-22621 for remote code… Full write-up → link in bio #cybersecurity #infosec #cve #kev #strapi https://t.co/VibEgtWecH

    0000034
    26 followersView on X
  • ♫Why♥Not♪@Python_s_

    #NØØT_Security_Alerts 🚨 #ALERT — CISA CONFIRMS EXPLOITATION OF STRAPI FLAW THAT CAN ENABLE ADMIN ACCOUNT TAKEOVER AND RCE CHAINING October 8, 2026 DISCLOSED BY: Strapi Security Team / CISA PRODUCT: Strapi Headless CMS CVE: CVE-2023-22894 RELATED: CVE-2023-22621 — Server-Side Template Injection AFFECTED VERSIONS: CVE-2023-22894: Strapi 3.2.1 through versions before 4.8.0. The vendor-documented RCE chain affects Strapi versions through 4.5.5. IMPACT: CVE-2023-22894 allows attackers to extract sensitive user information, including password hashes and password-reset tokens, through improper filtering of private fields. Strapi previously confirmed a research-demonstrated exploit chain combining CVE-2023-22894 with CVE-2023-22621. Under the documented conditions, attackers can hijack a super-administrator account and abuse vulnerable email templates to execute arbitrary server-side code. EXPLOITATION STATUS: CONFIRMED KNOWN EXPLOITATION. CVE-2023-22894 was added to CISA KEV on October 8, 2026. The vendor-documented RCE chain is technically demonstrated. CISA’s listing does not independently establish that the complete RCE chain is currently being exploited in the wild. knownRansomwareCampaignUse: Unknown — CISA. Forensic triage: Inspect unusual GET requests containing: password reset_password_token resetPasswordToken Review unexpected PUT requests to: /users-permissions/email-templates Investigate unauthorized administrative password resets, suspicious email-template modifications, and unexpected server-side processes. These indicators and investigation methods are documented by Strapi. URGENT ACTION: Identify legacy Strapi deployments. Upgrade to a currently supported release beyond the affected range. Review administrator accounts, preserve relevant application logs, and revoke potentially compromised sessions or reset tokens. Investigate potential compromise before rotating exposed credentials. SOURCE: https://strapi.io/blog/security-disclosure-of-vulnerabilities-cve CISA: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2023-22894 BACKUP: https://raw.githubusercontent.com/cisagov/kev-data/develop/known_exploited_vulnerabilities.json CONFIDENCE: VERY HIGH — CISA confirms known exploitation of CVE-2023-22894. Strapi independently documents and validates the vulnerability chain and defensive indicators. Current exploitation of the complete RCE chain remains unverified. #CyberSecurity #ThreatIntel #Strapi #CISA #KEV #RCE #WebSecurity #NØØT

    0000058
    229 followersView on X
  • CiberPlaneta@CiberPlanetaOrg

    🛡️ CVE-2023-22894: exposición de datos sensibles en Strapi CISA incorporó CVE-2023-22894 al catálogo KEV por explotación activa. La falla permite a usuarios con acceso al panel administrativo de Strapi descubrir datos sensibles mediante filtros de consulta y puede encadenarse con CVE-2023-22621 para lograr ejecución remota de código. https://www.ciberplaneta.org/vulnerabilidades/cve-2023-22894-exposicion-de-datos-sensibles-en-strapi/ #ciberplaneta #vulnerabilidades #cve_2023_22894 #cve #vulnerabilidad #strapi #seguridad #cisa_kev #infosec #ciberseguridad

    0000021
    7 followersView on X
  • CTIWatch@ctiwatchcloud
    Active Exploitation

    🚨 [HIGH] Active exploitation detected: CVE-2023-22621 Exploit in the wild confirmed for CVE-2023-22621 (CVSS null). Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can... 🔗 http://ctiwatch.cloud/alerts #ZeroDay #ExploitInWild #CyberSecurity

    Post summary

    CVE-2023-22621 is actively being exploited in the wild; the vulnerability is an authenticated SSTI in Strapi before version 4.5.5, and no patch or mitigation details are provided.

    00000126
    5.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appstrapistrapi---

Explore more