Strapi是法国strapi社区的一套开源的内容管理系统(CMS)。 Strapi 4.0.0版本至5.37.0之前版本存在路径遍历漏洞,该漏洞源于通过关系字段过滤内容时未充分清理查询参数,可能导致未经身份验证的攻击者使用where查询参数对admin_users表的私有字段执行布尔预言攻击,提取管理员重置令牌实现账户接管。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Strapi versions starting in 4.0.0 and prior to 5.37.0 did not sufficiently sanitize query parameters when filtering content via relational fields. An attacker could use the `where` query parameter on any publicly-accessible content-type with an `updatedBy` field to perform a boolean-oracle attack against private fields on the joined admin_users table, including the resetPasswordToken field, enabling full administrative account takeover without authentication. | https://github.com/projectdiscovery/nuclei-templates/blob/main/javascript/cves/2026/CVE-2026-27886.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2026-22706 | Strapi: Password Reset Does Not Revoke Existing Refresh Sessions | |
| CVE-2026-22707 | Strapi Upload Plugin MIME Validation Bypass via Content API | |
| CVE-2026-22599 | Strapi Vulnerable to SQL Injection in Content Type Builder | |
| CVE-2025-64526 | Strapi has a rate limit bypass on users-permissions plugin via attacker-controlled email k |
No comments yet