Executive brief
Strapi is an open-source content management system used to manage and deliver digital content. A security flaw in its user permissions plugin allows attackers to bypass rate limits on sensitive pages like login and password reset. This could enable malicious actors to perform high-volume automated attacks, such as guessing user passwords or reset codes, potentially leading to unauthorized account access.
Technical details
A rate-limit bypass exists in the Strapi users-permissions plugin due to improper rate-limit key generation. The middleware incorrectly incorporated an 'email' field from the request body into the rate-limit key even for routes where 'email' is not a valid or required field (such as /auth/local or /auth/reset-password). By providing a unique, arbitrary email value in each request, an unauthenticated attacker can generate a fresh rate-limit key, effectively neutralizing per-IP throttling. This enables large-scale credential stuffing and brute-force attacks against login and password reset endpoints. The vulnerability is addressed in version 5.45.0 by implementing an allow-list for routes that legitimately use the email field as an identifier.
Affected products
- Strapi Strapi plugin-users-permissions < 5.45.0
Timeline
- 2025-11-10: other: Vulnerability reported and fix initiated in PR #24818
- 2026-05-06: patched: Version 5.45.0 released
- 2026-05-14: advisory: NVD and GitHub Security Advisory published