{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3astrapistrapi/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:strapi:strapi:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.7,"id":"CVE-2026-90561"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Strapi (4.x \u003c= 4.26.2, 5.x \u003c 5.48.1)","Strapi (4.x-4.26.2)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Strapi"],"content_html":"\u003cp\u003eStrapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross-site scripting (XSS) vulnerability within the content manager's WYSIWYG preview component. The vulnerability exists because the application fails to adequately sanitize rich text fields, allowing for the injection of malicious script tags. An authenticated user possessing the 'Author' role can inject these scripts into content fields. When an 'Editor' or 'Super Admin' accesses the content and expands the preview pane, the malicious payload executes within their browser session. This flaw poses a significant risk for account takeover and unauthorized administrative access. Defenders should prioritize updating Strapi to the patched versions.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an authenticated attacker to execute arbitrary JavaScript in the context of high-privilege administrative sessions. This can lead to full account takeover of Editor or Super Admin accounts, unauthorized content manipulation, or the exfiltration of sensitive administrative data, significantly compromising the integrity and security of the Strapi content management environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all instances of Strapi to version 4.26.3 or 5.48.1 or later to remediate the sanitization failure associated with CVE-2026-90561.\u003c/li\u003e\n\u003cli\u003eReview user role assignments within the Strapi content manager to ensure that only trusted users are granted 'Author' privileges until patching is complete.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-14T13:04:08Z","date_published":"2026-09-13T11:25:30Z","id":"https://feed.craftedsignal.io/briefs/2026-09-strapi-xss/","summary":"Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 are vulnerable to stored XSS via the WYSIWYG preview component, allowing an authenticated Author to trigger script execution in high-privilege sessions.","title":"Stored Cross-Site Scripting Vulnerability in Strapi Content Manager","url":"https://feed.craftedsignal.io/briefs/2026-09-strapi-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:strapi:strapi:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}