Skip to content
Threat Feed
high advisory updated

Stored Cross-Site Scripting Vulnerability in Strapi Content Manager

Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 are vulnerable to stored XSS via the WYSIWYG preview component, allowing an authenticated Author to trigger script execution in high-privilege sessions.

CVE search metadata

CVE search record: CVE-2026-90561. Severity: high. CVSS: 8.7. KEV: no. Product: Strapi (4.x <= 4.26.2, 5.x < 5.48.1), Strapi (4.x-4.26.2). Brief: Stored Cross-Site Scripting Vulnerability in Strapi Content Manager. Brief link: https://feed.craftedsignal.io/briefs/2026-09-strapi-xss/

What's new

  • 1. new product Sep 14, 13:04 via bsi

Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross-site scripting (XSS) vulnerability within the content manager's WYSIWYG preview component. The vulnerability exists because the application fails to adequately sanitize rich text fields, allowing for the injection of malicious script tags. An authenticated user possessing the 'Author' role can inject these scripts into content fields. When an 'Editor' or 'Super Admin' accesses the content and expands the preview pane, the malicious payload executes within their browser session. This flaw poses a significant risk for account takeover and unauthorized administrative access. Defenders should prioritize updating Strapi to the patched versions.

Impact

Successful exploitation of this vulnerability allows an authenticated attacker to execute arbitrary JavaScript in the context of high-privilege administrative sessions. This can lead to full account takeover of Editor or Super Admin accounts, unauthorized content manipulation, or the exfiltration of sensitive administrative data, significantly compromising the integrity and security of the Strapi content management environment.

Recommendation

  1. Upgrade all instances of Strapi to version 4.26.3 or 5.48.1 or later to remediate the sanitization failure associated with CVE-2026-90561.
  2. Review user role assignments within the Strapi content manager to ensure that only trusted users are granted 'Author' privileges until patching is complete.

Mitigations

Upgrade Strapi to version 4.26.3 or 5.48.1

immediate IT Operations

CVE-2026-90561