Executive brief
Strapi is a popular open-source headless CMS and API platform used by developers to build web and mobile applications. By default, Strapi improperly allows any origin to access its API by reflecting the requesting domain in its CORS headers, enabling an attacker to trick a user's browser into revealing sensitive data through cross-origin requests without authentication barriers.
Technical details
The vulnerability is a CORS (Cross-Origin Resource Sharing) misconfiguration in Strapi's default configuration. The product reflects the Origin request header directly into the Access-Control-Allow-Origin response header without validation, combined with Access-Control-Allow-Credentials: true. This allows an attacker-controlled website to send credentialed HTTP requests to a Strapi backend instance and read sensitive API responses. The attack requires network access to both the target Strapi instance and the ability to trick a user into visiting a malicious website, but requires no authentication or special privileges. Strapi versions prior to 5.20.0 are affected; the vulnerability is patched in version 5.20.0 and later by properly whitelisting trusted origins.
Affected products
- Strapi Strapi < 5.20.0
Timeline
- 2025-10-16: disclosed
- 2025-10-16: patched: Fixed in version 5.20.0