Intel

AIKIDO-2026-10357

@strapi/core is vulnerable to Protection Mechanism Failure

Protection Mechanism Failure Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Mar 13, 2026

45

Medium Risk

This Affects:

JS@strapi/core
3.0.0 - 5.38.1
Fixed in 5.39.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package could allow inconsistent or overly permissive MIME validation during file uploads, causing the system to trust incorrect declared or stored content types, mishandle allow/deny rules, and persist misleading metadata such as application/octet-stream instead of the validated type. An attacker might exploit this by disguising a malicious file as an allowed format, abusing weak validation order or allow-list enforcement to upload content that is later served with an unsafe or misleading Content-Type, potentially increasing the risk of dangerous file delivery, content spoofing, or bypass of upload restrictions.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@strapi/core is vulnerable to Protection Mechanism Failure in versions 3.0.0 - 5.38.1.

How to fix this

Upgrade the @strapi/core library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform