Vulnerabilities/

Strapi Allows Unauthorized Access to Private Fields via parms.lookup

Severity:
High

Description

It’s possible to access any private fields by filtering through the lookup parameters

Recommendation

Update the @strapi/core package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@strapi/core
Anything's wrong? Let us know Last updated on October 16, 2025