SB2026042377 - Overly permissive cross-domain whitelist in strapi
Published: April 23, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Overly permissive cross-domain whitelist (CVE-ID: CVE-2025-53092)
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to permissive cross-domain security policy with untrusted domains in the CORS handling of @strapi/core when handling cross-origin requests. A remote attacker can host an attacker-controlled origin and send credentialed requests to disclose sensitive information.
Default installations reflect the Origin header in the Access-Control-Allow-Origin response header and allow credentials in cross-origin responses.
Remediation
Install update from vendor's website.