Junglewise Threat Intelligence

CVE-2024-56143: Strapi authorization bypass in lookup operator

CVE-2024-56143 · Severity: low · CVSS 3.1 · Published 2025-10-16

Technologies: @strapi/core (npm). Vendors: npm, Strapi.

Executive brief

Strapi, a popular open-source headless CMS, contains an authorization flaw in its lookup query operator that allows unauthenticated attackers to filter and extract private fields including admin passwords and password reset tokens. An attacker can exploit this by crafting specially formatted URL parameters to enumerate sensitive data and gain full administrative access to the Strapi instance without requiring any valid credentials.

Technical details

The vulnerability exists in Strapi's document service lookup operator (introduced in version 5.0.0), which fails to properly sanitize and filter access control checks for private fields. An unauthenticated, network-based attacker can construct HTTP requests with lookup parameters targeting protected fields such as admin passwords and reset tokens (e.g., `lookup[updatedBy][password][$startsWith]=$2`) to perform pattern-matching attacks. The lookup operator was not designed with proper authorization enforcement, allowing the attacker to iteratively filter results and eventually extract sensitive credentials. The vulnerability affects Strapi versions 5.0.0 through 5.5.1 and has been patched in version 5.5.2 via commit 0c6e095, which removes the lookup parameter from the document service.

Affected products

  • Strapi @strapi/core >= 5.0.0, < 5.5.2

Timeline

  • 2025-10-16: disclosed
  • 2025-10-16: patched: Version 5.5.2 and later
  • 2025-10-16: advisory

References

Related threats