CVE-2026-22707Disclosure(strapi / strapi)

LOWCVSS 5.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch strapi strapi systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Strapi is an open source headless content management system. In Strapi versions prior to 5.33.3, the Upload plugin's Content API endpoints did not enforce the administrator-configured MIME type restrictions (`plugin.upload.security.allowedTypes` and `deniedTypes`). The same restrictions were correctly enforced on the Admin Panel upload path. The upload plugin's `enforceUploadSecurity` security check was invoked in the admin upload controller but was missing from the Content API controller. The Content API handlers `uploadFiles` and `replaceFile` (and the `upload` wrapper that dispatches to them) called the underlying upload service directly, bypassing both the magic-byte MIME detection and the configured allow/deny lists. An authenticated user with the Content API upload permission could therefore upload file types the administrator had explicitly disallowed, including HTML and SVG content. In deployments serving uploaded files from the same origin as the admin panel (default), an attacker could upload an HTML or SVG file that, when opened directly by an admin, executed JavaScript in the admin origin, enabling admin-session hijack and authenticated administrative actions against the admin API. The patch in version 5.33.3 introduces a shared `prepareUploadRequest` helper that wraps `enforceUploadSecurity` and is called from both the Content API and admin upload controllers, ensuring identical security policy enforcement on every upload entry point.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434CWE-693

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • strapi

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
strapi

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-13: 1Patch / Workaround · 2026-05-13: 105-13
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • kaminuma@kaminuma_dev
    Disclosure

    A vulnerability I reported to Strapi is now public: CVE-2026-22707 Thanks to the maintainers for the fix and disclosure. Advisory: https://github.com/strapi/strapi/security/advisories/GHSA-pcw7-5633-82vv #CVE #AppSec #Security #Strapi

    Post summary

    The user announces that the Strapi CVE-2026-22707 is publicly disclosed, acknowledging a fix and providing an advisory link.

    0001096
    137 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appstrapistrapi-node.js-

Explore more