Description
It’s possible to access any private fields by filtering through the lookup parameters
Recommendation
Update the @strapi/core package to the latest compatible version. Followings are version details:
- Affected version(s): >= 5.0.0, < 5.5.2
- Patched version(s): 5.5.2
References
Related Issues
- Strapi core vulnerable to sensitive data exposure via CORS misconfiguration - CVE-2025-53092
- Redwood is vulnerable to account takeover via dbAuth "forgot-password - Vulnerability
- Follow Redirects improperly handles URLs in the url.parse() function - CVE-2023-26159
- Exposure of Sensitive Information to an Unauthorized Actor in nanoid - CVE-2021-23566
- Tags:
- npm
- @strapi/core
Anything's wrong? Let us know Last updated on October 16, 2025