Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-90561: Strapi content preview lets author inject scripts
CVE-2026-90561 · published 27 days ago
Summary
Strapi versions up to 4.26.2 and before 5.48.1 allow a user with author rights to save malicious code in rich‑text fields. When an editor or super‑admin opens the preview pane, that code runs in their browser, potentially letting the attacker take over the account. Update Strapi to the latest release or apply the vendor’s patch to fix the preview handling.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| strapi | strapi | <= 4.26.2 |
Original advisory text
Strapi 4.x through 4.26.2 and 5.x before 5.48.1 Stored XSS via WYSIWYG
Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross-site scripting vulnerability in the content manager WYSIWYG preview component that fails to strip script tags from rich text. An Author-role user can store malicious script tags in rich text fields that execute in an Editor or Super Admin's session when the preview pane is expanded, enabling account takeover.
References
- https://www.vulncheck.com/advisories/strapi-4-x-through-4.26.2-and-5-x-before-5....
- https://github.com/strapi/strapi/issues/26857
- https://github.com/strapi/strapi
- https://github.com/strapi/strapi/blob/v5.46.0/packages/core/content-manager/admi...
- https://github.com/strapi/strapi/commit/875752612c30f951546904a29469e51e17e0ac37
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90561... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-90561 Vendor Advisory
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-79Cross-site Scripting (XSS)
Timeline
Published13 Sep 2026
Updated9 Oct 2026
First seen13 Sep 2026
Track software like this
Free during beta