Stored Cross-Site Scripting in Strapi Content Manager WYSIWYG Component
CVE-2026-90561
9.3CRITICAL
What is CVE-2026-90561?
Strapi versions 4.x up to 4.26.2 and 5.x prior to 5.48.1 are susceptible to a stored cross-site scripting vulnerability in the WYSIWYG preview component of the content manager. This flaw allows users with the Author role to insert malicious script tags into rich text fields. When the preview pane is accessed by an Editor or Super Admin, the scripts execute within their session, potentially leading to an account takeover. Proper validation of input and scripts within this component is essential to prevent such security breaches.
Affected Version(s)
strapi 4.0.0 <= 4.26.2
strapi 5.0.0 < 5.48.1
