Description
It’s possible to access any private fields by filtering through the lookup parameters
Recommendation
Update the @strapi/core package to the latest compatible version. Followings are version details:
- Affected version(s): >= 5.0.0, < 5.5.2
- Patched version(s): 5.5.2
References
Related Issues
- Unauthorized Access to Private Fields in User Registration API (GHSA-gc7p-j5xm-xxh2) - CVE-2023-39345
- Unauthorized Access to Private Fields in User Registration API - CVE-2023-39345
- @strapi/plugin-content-manager leaks data via relations via the Admin Panel - CVE-2024-29181
- Vditor allows Cross-site Scripting via an attribute of an `A` element - CVE-2024-34449
- Tags:
- npm
- @strapi/core
Anything's wrong? Let us know Last updated on October 16, 2025