Impact
Strapi versions 4.x up to 4.26.2 and 5.x before 5.48.1 contain a stored cross‑site scripting flaw (CWE‑79) in the content manager WYSIWYG preview component. The component fails to strip <script> tags from rich‑text fields, allowing an Author‑role user to embed malicious scripts. When a privileged user, such as an Editor or a Super Admin, opens the preview pane the malicious code executes in that user’s session, effectively granting the attacker control over the account.
Affected Systems
Strapi, the open‑source headless CMS, is affected. The vulnerability exists in all 4.x releases up to 4.26.2 and in all 5.x releases prior to 5.48.1. Only these versions allow authors to store script tags in rich‑text content that will later be rendered in a preview pane.
Risk and Exploitability
The CVSS score of 9.3 marks the flaw as high‑severity. EPSS is < 1% and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to have Author‑role privileges to inject malicious script and then requires a privileged user to open the preview pane for the code to run. The likely attack vector is, and the impact is a full account takeover of privileged accounts, enabling compromise of confidentiality, integrity, and availability of the system.
OpenCVE Enrichment