Vulnerabilities/

Strapi core vulnerable to sensitive data exposure via CORS misconfiguration

Severity:
Medium

Description

A CORS misconfiguration vulnerability exists in default installations of Strapi where attacker-controlled origins are improperly reflected in API responses.

Recommendation

Update the @strapi/core package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@strapi/core
Anything's wrong? Let us know Last updated on October 16, 2025