Description
It’s possible to access any private fields by filtering through the lookup parameters
Recommendation
Update the @strapi/core package to the latest compatible version. Followings are version details:
- Affected version(s): >= 5.0.0, < 5.5.2
- Patched version(s): 5.5.2
References
Related Issues
- Strapi Password Hashing is Missing Maximum Password Length Validation - CVE-2025-25298
- Redwood is vulnerable to account takeover via dbAuth "forgot-password - Vulnerability
- Exposure of Sensitive Information to an Unauthorized Actor in nanoid - CVE-2021-23566
- AngularJS allows attackers to bypass common image source restrictions - CVE-2024-8372
- Tags:
- npm
- @strapi/core
Anything's wrong? Let us know Last updated on October 16, 2025