<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Strapi (4.x &lt;= 4.26.2, 5.x &lt; 5.48.1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/strapi-4.x--4.26.2-5.x--5.48.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 13 Sep 2026 11:25:30 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/strapi-4.x--4.26.2-5.x--5.48.1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored Cross-Site Scripting Vulnerability in Strapi Content Manager</title><link>https://feed.craftedsignal.io/briefs/2026-09-strapi-xss/</link><pubDate>Sun, 13 Sep 2026 11:25:30 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-strapi-xss/</guid><description>Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 are vulnerable to stored XSS via the WYSIWYG preview component, allowing an authenticated Author to trigger script execution in high-privilege sessions.</description><content:encoded><![CDATA[<p>Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross-site scripting (XSS) vulnerability within the content manager's WYSIWYG preview component. The vulnerability exists because the application fails to adequately sanitize rich text fields, allowing for the injection of malicious script tags. An authenticated user possessing the 'Author' role can inject these scripts into content fields. When an 'Editor' or 'Super Admin' accesses the content and expands the preview pane, the malicious payload executes within their browser session. This flaw poses a significant risk for account takeover and unauthorized administrative access. Defenders should prioritize updating Strapi to the patched versions.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows an authenticated attacker to execute arbitrary JavaScript in the context of high-privilege administrative sessions. This can lead to full account takeover of Editor or Super Admin accounts, unauthorized content manipulation, or the exfiltration of sensitive administrative data, significantly compromising the integrity and security of the Strapi content management environment.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade all instances of Strapi to version 4.26.3 or 5.48.1 or later to remediate the sanitization failure associated with CVE-2026-90561.</li>
<li>Review user role assignments within the Strapi content manager to ensure that only trusted users are granted 'Author' privileges until patching is complete.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>