An open source headless CMS solution to create and manage your own API. It provides a powerful dashboard and features to make your life easier. Databases supported: MySQL, MariaDB, PostgreSQL, SQLite
83%
Total Score
63
100
100
100
50
| Title | Versions | Severity |
|---|---|---|
CVE-2026-27886 @strapi/strapi is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 4.0.0 - 5.37.0. | 4.0.0 - 5.37.0 | Critical |
CVE-2025-3930 @strapi/strapi is vulnerable to Insufficient Session Expiration in versions 0.0.0 - 5.24.1. | 0.0.0 - 5.24.1 | Medium |
AIKIDO-2025-10134 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @strapi/strapi is vulnerable to Race Condition in versions 4.6.0 - 5.10.4. | 4.6.0 - 5.10.4 | Low |
CVE-2024-37818 @strapi/strapi is vulnerable to Server-Side Request Forgery (SSRF) in versions 4.24.4 - 4.24.4. | 4.24.4 - 4.24.4 | High |
AIKIDO-2024-10092 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @strapi/strapi is vulnerable to URL Redirection to Untrusted Site ('Open Redirect') in versions 4.0.0 - 4.24.1. | 4.0.0 - 4.24.1 | High |
| Dependency | Last Release | Score |
|---|---|---|
ora Version 5.4.1 | — | — |
yup Version 0.32.9 | — | — |
vite Version 5.4.21 | — | — |
boxen Version 5.1.2 | — | — |
chalk Version 4.1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant