Strapi Cleartext Storage of Sensitive Information Vulnerability

🚨SEVERITY: MEDIUM — CVSS 4.9Security Advisory

TL;DR 📌

  • Strapi contains a cleartext storage of sensitive information vulnerability that could allow attackers with access to the admin panel to discover sensitive user details via the query filter. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. This vulnerability can be chained…
  • Highest CVSS: 4.9 (Medium).
  • Listed in CISA KEV (2026-10-08) — this is being exploited in the wild.
  • Fixed in 4.8.0 — upgrade to this release or later.
  • CVEs: CVE-2023-22894.

What it is

Strapi contains a cleartext storage of sensitive information vulnerability that could allow attackers with access to the admin panel to discover sensitive user details via the query filter. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. This vulnerability can be chained with CVE-2023-22621 to achieve remote code execution.

For leadership 🧭

Executive summary. Risk is Medium (CVSS 4.9) across any Strapi kit you run. Follow the remediation in the vendor advisory within Immediate — CISA KEV entries carry a federal remediation deadline.

Why it matters:

  • Exposure depends on deployment topology and which access paths reach the affected component.
  • Treat internet-facing and management-plane instances as higher risk than internal-only ones.
  • Keep monitoring for abnormal authentication and configuration events until upgrades complete.

Now / Next / Later:

  • Now: confirm whether you run the affected versions, and check exposure of any that are internet-facing.
  • Next: apply the remediation the advisory specifies, through an approved change window.
  • Later: add a control check so builds cannot drift back onto a vulnerable train.

Source