Intel

AIKIDO-2026-10088

@strapi/core is vulnerable to Improper Access Control

Improper Access Control Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jan 26, 2026

75

High Risk

This Affects:

JS@strapi/core
4.0.0 - 4.26.0
Fixed in 4.26.1
5.0.0 - 5.33.1
Fixed in 5.33.2
Are you affected? Scan for Free

TL;DR

Affected versions of this package expose write APIs outside of development mode, allowing unintended write operations in non-development environments and increasing the risk of unauthorized data modification.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@strapi/core is vulnerable to Improper Access Control in versions 5.0.0 - 5.33.1 and 4.0.0 - 4.26.0.

How to fix this

Upgrade the @strapi/core library to a patch version.