Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Strapi <4.5.0: sanitize-html XSS via outdated DOMPurify config, fixed by migration

Security Advisory High Strapi
Affected:
  • strapi v4.5.0
  • strapi versions prior to v4.5.0 using sanitize-html
Fixed in:
  • strapi v4.5.0 (commit 8757526)
Referenced CVEs: CVE-2026-90561 · 8.7
文章内图片已隐藏以节省流量 · Upgrade to Pro to view images & offline archive

This content was auto-fetched from github.com, cleaned by our LLM pipeline, and translated to English. View original.
More from this source
Offline Archive

Offline screenshot & PDF are Pro-exclusive

Upgrade to Pro