VDB
Sign up
HIGH7.5

GHSA-9329-mxxw-qwf8

Strapi core vulnerable to sensitive data exposure via CORS misconfiguration

Quick fix

GHSA-9329-mxxw-qwf8 — @strapi/core: upgrade to the fixed version with the command below.

npm install @strapi/core@5.20.0

Details

### Summary

A CORS misconfiguration vulnerability exists in default installations of Strapi where attacker-controlled origins are improperly reflected in API responses.

### Technical Details

By default, Strapi reflects the value of the Origin header back in the Access-Control-Allow-Origin response header without proper validation or whitelisting.

Example: `Origin: http://localhost:8888` `Access-Control-Allow-Origin: http://localhost:8888` `Access-Control-Allow-Credentials: true`

This allows an attacker-controlled site (on a different port, like 8888) to send credentialed requests to the Strapi backend on 1337.

### Suggested Fix

1. Explicitly whitelist trusted origins 2. Avoid reflecting dynamic origins

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@strapi/core
Introduced in: 0Fixed in: 5.20.0
Fixnpm install @strapi/core@5.20.0

References