Intel

AIKIDO-2026-10627

strapi-plugin-magic-sessionmanager is vulnerable to Authorization Bypass

Authorization Bypass Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Apr 28, 2026

80

High Risk

This Affects:

JSstrapi-plugin-magic-sessionmanager
1.0.0 - 4.5.4
Fixed in 4.5.5
Are you affected? Scan for Free

TL;DR

All admin API routes were protected only by admin::isAuthenticatedAdmin, which authenticates an admin session but does not enforce whether the admin role has the plugin-specific permission.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

strapi-plugin-magic-sessionmanager is vulnerable to Authorization Bypass in versions 1.0.0 - 4.5.4.

How to fix this

Upgrade the strapi-plugin-magic-sessionmanager library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform