GHSA-jh7v-p6jw-jwhcCriticalCVSS 8.7
Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross-site scripting...
🔗 CVE IDs covered (1)
📋 Description
Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross-site scripting vulnerability in the content manager WYSIWYG preview component that fails to strip script tags from rich text. An Author-role user can store malicious script tags in rich text fields that execute in an Editor or Super Admin's session when the preview pane is expanded, enabling account takeover.
🔗 References (7)
- https://nvd.nist.gov/vuln/detail/CVE-2026-90561
- https://github.com/strapi/strapi/issues/26857
- https://github.com/strapi/strapi/commit/875752612c30f951546904a29469e51e17e0ac37
- https://github.com/strapi/strapi
- https://github.com/strapi/strapi/blob/v5.46.0/packages/core/content-manager/admin/src/pages/EditView/components/FormInputs/Wysiwyg/PreviewWysiwyg.tsx
- https://www.vulncheck.com/advisories/strapi-4-x-through-4.26.2-and-5-x-before-5.48.1-stored-xss-via-wysiwyg
- https://github.com/advisories/GHSA-jh7v-p6jw-jwhc