Strapi CVE-2023-22894: a CVSS-4.9 bug that chains to unauthenticated RCE
Strapi CVE-2023-22894 reads like a medium-severity info leak, but it chains to unauthenticated RCE on end-of-life CMS instances — and CISA just added it to KEV.
Published by Zero Hunt, an autonomous AI red team on an on-premise appliance running private AI: automated penetration testing for networks and infrastructure, black-box or gray-box, with a human approving every step that matters.
On October 8, 2026 CISA added CVE-2023-22894 — a 2023 Strapi flaw — to its Known Exploited Vulnerabilities catalog with a federal remediation deadline of October 11, three days out. On paper the bug is unremarkable: NVD scores it 4.9, medium, and files it as an information-disclosure issue requiring high privileges. That score is the trap. The researchers who originally reported it demonstrated that CVE-2023-22894 can be driven unauthenticated, and that it chains with a second Strapi bug into remote code execution on any instance running an affected end-of-life build. KEV additions mean one thing: someone is already using it.
Developing story — first published 20:05 CEST (18:05 UTC), October 8, 2026. Updated as the vendor and CISA publish more.
At a glance
| CVE | CVE-2023-22894 |
| Product / affected versions | Strapi (@strapi/strapi) · >= 3.2.1, < 4.8.0 |
| Fixed in | 4.8.0 (released March 15, 2023); the RCE-chain partner CVE-2023-22621 was fixed in 4.5.6 (January 11, 2023) |
| CVSS | 4.9 Medium · CVSS 3.1 · NVD/NIST · AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N. CNA secondary scored 7.2 High · AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
| Exploited in the wild | Yes · CISA KEV (added 2026-10-08) |
| CISA KEV | Added 2026-10-08; federal due date 2026-10-11 (BOD 26-04); forensic triage not required |
| Public PoC | Yes — the vendor disclosure and the original researcher write-up both document the full chain |
| Official advisory | Strapi security disclosure |
Why CVE-2023-22894 is not a medium-severity bug
Strapi is one of the most widely deployed open-source headless CMSs, and its content APIs sit directly on the public internet by design. CVE-2023-22894 is a query-filter flaw: Strapi correctly strips private fields like password and reset_password_token from API responses, but it does not strip them from the query it runs against the database. An attacker can therefore filter on a field they can never read.
That turns into a blind oracle. Using filter operators such as $startsWith, you ask the API a yes/no question one character at a time — does the admin password hash start with $2a? does the reset token start with f? — and watch whether the result set changes. Character by character, exactly like a blind SQL injection, the secret falls out.
The reason this is unauthenticated, despite NVD's PR:H vector, is the relational model. Any public collection with find permission — an articles or comments endpoint, the kind every Strapi site exposes — carries auto-generated createdBy and updatedBy relations that point straight at the admin user table. The original research by ghostccamm shows the full path:
filters[$and][0][createdBy][email][$startsWith]=aleaks the admin email a letter at a time. Trigger a password reset for that account, then leakreset_password_tokenwith the same technique, set a new password, and you hold Super Administrator.
From Super Admin, the second bug finishes the job. CVE-2023-22621 is a server-side template injection in the users-permissions email templates: Strapi renders them through lodash's _.template(), and the validation regex can be bypassed. An attacker who owns the admin panel edits the confirmation-email template with a <%= %> payload that spawns a shell, enables email confirmation, and registers a user to fire it. The Strapi disclosure confirms the two combine into unauthenticated RCE on all Strapi <= 4.5.5. The 4.9 score describes the first link in isolation; the real-world outcome is code execution as the application process.
Who is exposed and how to check
- The information-disclosure primitive affects Strapi >= 3.2.1, < 4.8.0.
- The full unauthenticated-RCE chain requires the SSTI partner and so hits Strapi <= 4.5.5.
- Strapi v3 and early v4 are end-of-life — which is exactly why CISA's KEV entry tells operators to move to a supported version rather than assuming a patch exists for their branch.
Check your running version fast: the admin panel footer shows it, npm ls @strapi/strapi (or cat package.json) reports the installed package, and the /admin build often fingerprints the release. If the number is below 4.8.0 and the service is reachable from the internet, treat it as exposed now.
Remediation
1. Am I affected? Confirm the version (npm ls @strapi/strapi, package.json, or the admin footer). Inventory every public collection type and check whether find is enabled for the public role — those are the endpoints that leak createdBy.
2. Patch — exact fixed versions. Upgrade to 4.8.0 or later, which closes the filter leak; the email-template SSTI was fixed back in 4.5.6. If you are on v3 or an early v4 that is out of support, the fix is a migration to a maintained branch, not a point release — plan it as such.
3. Can't patch now? Compensating controls. At the reverse proxy or WAF, block query strings that filter on sensitive or relational columns — reject requests containing [password], [reset_password_token], [resetPasswordToken], or $startsWith/$contains operators nested under createdBy/updatedBy. Remove the public find permission from any collection that does not strictly need it. Lock down the users-permissions email templates and disable public registration / email confirmation until patched. Put the admin panel behind VPN or IP allow-listing.
4. Hunt for compromise. Using only the indicators the researcher and vendor published, review logs for:
- Filter parameters targeting
email,password, orreset_password_token— regex(\[|%5B)\s*(email|password|reset_password_token)\s*(\]|%5D)— especially in bursts of near-identical requests (the blind oracle is loud). Maps to MITRE ATT&CK T1190 (Exploit Public-Facing Application) and T1212 (Exploitation for Credential Access). - Password-reset requests immediately followed by many filtered queries, then an admin login from a new IP — the account-takeover sequence.
PUTrequests to/users-permissions/email-templateswhose body carries lodash<%= %>delimiters with JavaScript — the SSTI write, ATT&CK T1059 (Command and Scripting Interpreter).- New or unexpected admin accounts and newly triggered user registrations coinciding with a template change.
5. Eradicate + verify. If you see those patterns, assume Super Admin was taken: rotate every admin credential, invalidate all reset_password_token values, rotate the JWT_SECRET and the ADMIN_JWT_SECRET, and revoke and reissue API tokens. Audit every email template for injected delimiters. Rebuild the instance from a known-good image rather than cleaning in place, then re-test the filter oracle after patching to confirm it no longer answers.
What is not known yet
CISA's entry marks known ransomware use as Unknown and does not name a threat actor, a campaign, or a victim count. The KEV listing confirms exploitation is happening but not its scale, whether it is opportunistic internet-wide scanning or targeted, or how far the EoL population still reachable on the public internet extends. We will update this post as the vendor, CISA, or incident responders publish more.
Where this leaves you
The lesson of CVE-2023-22894 is that a severity score is a label, not a measurement of your exposure. A PR:H, 4.9 "medium" became an unauthenticated path to Super Admin and then to code execution — and no scanner that keys off CVSS would have ranked it anywhere near the top of your queue. The only way to know what a vulnerability actually does to your deployment is to run the chain against it the way an attacker would.
That is what Zero Hunt's autonomous AI red team does: a 10-agent swarm, running on-premise on private models with a human in the loop for anything that touches a live system, fingerprints the exact Strapi build, then has a sealed coding agent write and iterate a proof-of-concept for this specific chain until it demonstrably works — black-box, the way the real attacker reaches it, not a signature lookup that trusts the 4.9. If the chain fires, you get a signed, reproducible exploit filed against the asset, not a "medium" ticket that sits for a quarter. And because the filter oracle is so loud — hundreds of near-identical requests inferring a secret one byte at a time — Zero Hunt's traffic-analysis model, four inference heads running on the appliance GPU at wire speed, flags that brute-force pattern while it is happening, which for an end-of-life CMS you cannot cleanly patch is often the only control you have left. See the automated penetration testing guide for how continuous, proof-driven validation closes the gap a CVSS number leaves open, or get in touch.
Every vulnerability CISA lists as exploited, with federal due dates: CISA KEV tracker →
Is this exploitable in your environment?
Zero Hunt answers that on your own network: an autonomous AI red team on an on-premise appliance, running on private AI, black-box or gray-box, with a human approving every step that matters. Proof of what is exploitable, the fix, and signed evidence — no data leaves your perimeter.