What is Strapi?
Strapi is an open-source headless CMS written in Node.js. Instead of rendering web pages, it stores structured content and exposes it over REST and GraphQL APIs that front-end applications, mobile apps, and other services consume. Developers define content types in an admin panel, and Strapi generates the database schema, the API endpoints, and a role-based permission model around them. It is one of the most widely self-hosted Node.js content back ends, which means a typical deployment holds an organisation's content, its API consumer accounts, and a set of administrator accounts, all behind an HTTP API that is often reachable from the internet by design.
Overview
CVE-2023-22894 is a private field disclosure flaw in Strapi's query filtering. Strapi marks certain database columns private, notably password and resetPasswordToken, and strips them from API responses. The mistake was that it stripped them from the results only, not from the query. An attacker could still filter on a private column, and the server would faithfully apply the filter and return the matching records.
That turns a hidden value into an oracle. Using an operator such as $startsWith, an attacker submits a filter on resetPasswordToken beginning with a, observes whether any record comes back, and repeats character by character until the whole token is reconstructed. The researcher's description is exact: the technique is equivalent to blind SQL injection, except the application is cooperating rather than being tricked into it.
The impact depends on who can reach a filterable endpoint, and the range is wide. A super admin can dump the password hashes and reset tokens of every account. A lower-privileged editor or author can extract the same material for API users. The worst case is unauthenticated: Strapi automatically creates createdBy and updatedBy relations from content entries to admin users, so any publicly readable collection can be filtered through that relation to reach an administrator's reset token. With the token, the attacker completes a password reset, takes over the super admin account, and on Strapi 4.5.5 or earlier can chain CVE-2023-22621, a server-side template injection in the users-permissions email templates, into remote code execution.
Scoring reflects the disagreement over scope. NVD rates it 4.9 Medium with high privileges required (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N), matching the admin-panel reading of the flaw. The Belgian Centre for Cybersecurity and other trackers rate it 9.8 Critical, matching the unauthenticated-via-relations reading. The researcher's own account supports the higher figure. Treat the Medium rating in the frontmatter above as the NVD position, not as the practical risk.
Affected Versions
| Product | Vulnerable | Fixed |
|---|---|---|
| Strapi (@strapi/strapi) | 3.2.1 through 4.7.x | 4.8.0 |
| Strapi, chained RCE with CVE-2023-22621 | 4.5.5 and earlier | 4.5.6 for the SSTI, 4.8.0 for this flaw |
| Strapi, filter validation bypass CVE-2023-34235 | 4.10.7 and earlier | 4.10.8 |
Sources state the range differently: MITRE says "through 4.5.5", the researcher says 4.7.1 and below, and Strapi's own advisory says 3.2.1 up to but not including 4.8.0. Strapi's range is the one to plan against. CISA notes the product may be end of life or end of service in the deployed version; Strapi 3.x is unsupported and has no fix. Note also that the 4.8.0 patch was incomplete: the same researcher bypassed it through SQL table aliases, tracked as CVE-2023-34235 and fixed in 4.10.8, so 4.8.0 is a floor rather than a destination.
Technical Details
CISA's catalog maps this to CWE-312, cleartext storage of sensitive information, which does not describe the mechanism well. Nothing here is stored in cleartext; passwords are hashed. The accurate description is an authorization gap in query construction, closer to CWE-200 information exposure: the access control that governed output was not applied to input. Strapi sanitised the response object but passed user-supplied filter keys straight through to the query builder.
The attack is a sequence of ordinary GET requests with filter parameters, for example a filter on a relation path ending at createdBy with a $startsWith condition on resetPasswordToken. Each request is valid, authenticated at whatever level the endpoint requires, and returns a normal response; only the pattern of hits and misses leaks data. Extracting a full token takes on the order of hundreds to a few thousand requests, trivially scriptable.
Strapi's fix was substantial, touching more than 280 files: query parameters are sanitised, column names are validated, and a global search operator now honours a searchable attribute on fields. That breadth is itself a signal of how deeply the assumption ran through the codebase, and explains why an edge case involving table aliases survived into CVE-2023-34235.
Discovery
The vulnerability was found and reported by the researcher who publishes as GhostCcamm. They reported it to Strapi on 2023-01-03 as a Medium-severity issue requiring admin access, escalated it to Critical on 2023-01-18 after finding the unauthenticated path, and on 2023-01-21 supplied Strapi with a working unauthenticated RCE chain combining this flaw with CVE-2023-22621. Strapi provided a patch for testing on 2023-02-23, the researcher confirmed it on 2023-03-05, and 4.8.0 shipped on 2023-03-15. Public disclosure followed on 2023-04-17, deliberately held until the fix was out, and Strapi paid a bounty. The full proof of concept for the chain was withheld.
Exploitation Context
CISA added the CVE to the KEV catalog on 2026-10-08, which is the authoritative statement that exploitation has been observed. Contemporary 2023 reporting did not document a named campaign: vendor trackers at the time recorded published proof-of-concept material but no confirmed in-the-wild use, and no threat actor, ransomware family, or botnet has been publicly tied to this CVE. CISA marks it as not known to be used in ransomware campaigns.
What makes it attractive now is the chain rather than the leak. A self-hosted Strapi that has not been updated since early 2023 is likely to be on 4.5.x or older, which means both this flaw and the CVE-2023-22621 template injection are present and the full path from unauthenticated request to code execution is available in a single automated script. No reliable exposure count exists for internet-facing Strapi instances at vulnerable versions; the admin panel is recognisable at /admin but the version is not consistently advertised.
Remediation
- Upgrade to a current Strapi 5.x release. If that is not immediately possible, 4.10.8 is the minimum that includes both this fix and the CVE-2023-34235 bypass fix; 4.8.0 alone is not sufficient.
- If you are on 4.5.5 or earlier, treat CVE-2023-22621 as part of the same emergency. The combination is what turns this into unauthenticated remote code execution.
- Assume credentials are exposed on any instance that ran a vulnerable version while reachable by untrusted users. Reset all admin and API user passwords, invalidate outstanding password reset tokens, rotate API tokens and the
JWT_SECRETandADMIN_JWT_SECRETvalues, and review the admin user list for accounts you did not create. - Restrict reach. The
/adminpanel rarely needs to be open to the internet; put it behind a VPN or an IP allowlist, and review public role permissions so that collections exposingcreatedByorupdatedByrelations are not readable anonymously. - Search your logs. Exploitation is visible because the payload sits in GET query parameters, which web servers and proxies log by default. Grep access logs for filter parameters naming
password,resetPasswordToken, oremail, and for long runs of near-identical requests with$startsWithconditions from one source. For the chained SSTI, look for PUT requests to/users-permissions/email-templates. - If the deployed version is end of life and cannot be upgraded, CISA's required action allows for discontinuing use of the product; plan a migration rather than leaving an unfixable instance exposed.
- Federal civilian agencies must remediate by 2026-10-11 under BOD 26-04 and perform the forensic triage the directive requires.
Key Details
| Property | Value |
|---|---|
| CVE ID | CVE-2023-22894 |
| Vendor / Product | Strapi — Strapi |
| NVD Published | 2023-04-19 |
| NVD Last Modified | 2026-10-08 |
| CVSS 3.1 Score | 4.9 |
| CVSS 3.1 Vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
| Severity | MEDIUM |
| CWE | CWE-312 find similar ↗ |
| CISA KEV Added | 2026-10-08 |
| CISA KEV Deadline | 2026-10-11 |
| Known Ransomware Use | No |
CVSS 3.1 Breakdown
Required Action
Timeline
| Date | Event |
|---|---|
| 2023-01-03 | GhostCcamm reports the private field filtering issue to Strapi as Medium severity; Strapi acknowledges the same day |
| 2023-01-18 | Researcher finds an unauthenticated path to the leak and raises the severity to Critical |
| 2023-01-21 | Proof of concept for unauthenticated RCE, chaining this flaw with CVE-2023-22621, sent to Strapi |
| 2023-03-15 | Strapi 4.8.0 released with the fix |
| 2023-04-17 | Public disclosure in the researcher's write-up and Strapi's security blog post |
| 2023-04-19 | CVE-2023-22894 record published |
| 2026-10-08 | Added to CISA Known Exploited Vulnerabilities catalog |
| 2026-10-11 | CISA BOD 26-04 remediation deadline |
References
| Resource | Type |
|---|---|
| NVD - CVE-2023-22894 | Vulnerability Database |
| CISA KEV Catalog Entry | US Government |
| Strapi - Security Disclosure of Vulnerabilities: CVE-2023-22893, CVE-2023-22621 and CVE-2023-22894 | Vendor Advisory |
| GhostCcamm - Multiple Critical Vulnerabilities in Strapi Versions 4.7.1 and Below | Security Research |
| GhostCcamm - CVE-2023-34235, Bypassing the Filter Validation Fix in Strapi 4.10.7 and Below | Security Research |
| Belgian Centre for Cybersecurity - Warning on Unauthenticated RCE in Strapi Servers | Security Research |
| Strapi Releases - Version History and Changelogs | Vendor Advisory |