CVE-2026-90561

Source
https://cve.org/CVERecord?id=CVE-2026-90561
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90561.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90561
Published
2026-09-13T10:45:35Z
Modified
2026-09-15T03:48:24Z
Severity
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N CVSS Calculator
Summary
Strapi 4.x through 4.26.2 and 5.x before 5.48.1 Stored XSS via WYSIWYG
Details

Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross-site scripting vulnerability in the content manager WYSIWYG preview component that fails to strip script tags from rich text. An Author-role user can store malicious script tags in rich text fields that execute in an Editor or Super Admin's session when the preview pane is expanded, enabling account takeover.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-79"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90561.json"
}
References

Affected packages

Git / github.com/strapi/strapi

Affected ranges

Type
GIT
Repo
https://github.com/strapi/strapi
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "4.0.0"
        },
        {
            "last_affected": "4.26.2"
        },
        {
            "introduced": "5.0.0"
        },
        {
            "fixed": "5.48.1"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

v4.*
v4.25.16
v4.25.22
v5.*
v5.0.0
v5.0.2-beta.0
v5.0.4
v5.14.0
v5.24.1
v5.31.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90561.json"