Executive brief
Strapi is a popular headless CMS (content management system) used to manage digital content for websites and applications. In version 4.1.12, the Media Library feature allows authenticated users to upload files without proper validation. An attacker can upload a file containing malicious code, and when another user opens the file's link, the attacker's script runs in their browser—potentially stealing login credentials, session tokens, or redirecting them to malicious sites.
Technical details
This is a stored cross-site scripting (XSS) vulnerability in Strapi's Media Library upload functionality. The vulnerability arises from insufficient input validation and output encoding on uploaded files. An authenticated attacker with Media Library upload permissions can craft and upload a file containing malicious JavaScript or HTML (e.g., a PDF or other document with embedded XSS payload). When a victim clicks "copy link" and opens the file URL in a browser, the payload executes in their security context. The attack requires prior authentication and victim interaction (opening the link), but no special privileges beyond basic file-upload permissions. The vulnerability affects Strapi v4.1.12 and likely earlier versions. Patches and configuration hardening via file-type restrictions and Content-Security-Policy headers are recommended.
Affected products
- Strapi @strapi/strapi 4.1.12 and likely earlier versions
Timeline
- 2022-05-29: disclosed: Vulnerability publicly disclosed
- 2022-07-14: advisory: CVE-2022-32114 reserved; GHSA-4vm8-j95f-j6v5 published
References
- https://docs.strapi.io/dev-docs/configurations/public-assets
- https://docs.strapi.io/user-docs/users-roles-permissions/configuring-administrator-roles
- https://github.com/bypazs/strapi
- https://github.com/strapi/strapi
- https://github.com/strapi/strapi/blob/d9277d616b4478a3839e79e47330a4aaf167a2f1/packages/core/content-type-builder/admin/src/components/AllowedTypesSelect/index.js
- https://github.com/strapi/strapi/blob/d9277d616b4478a3839e79e47330a4aaf167a2f1/packages/core/upload/admin/src/components/MediaLibraryInput/index.js