PT-2025-42484 · Strapi · Strapi

Published

2025-10-16

·

Updated

2025-11-25

·

CVE-2024-56143

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Strapi versions 5.0.0 through 5.5.1
Description Strapi is an open-source headless content management system. A flaw in the document service lookup does not properly sanitize query parameters for private fields. This allows an attacker to access private fields, including admin passwords and reset tokens, by crafting queries with the lookup parameter.
Recommendations Update to version 5.5.2 or later.

Exploit

Fix

LPE

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-56143
GHSA-495J-H493-42Q2

Affected Products

Strapi