PatchSiren

strapi CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL strapi CVE published 2026-09-13

CVE-2026-90561

CVE-2026-90561 is a critical stored cross-site scripting vulnerability in Strapi instances, allowing malicious script execution in certain user sessions. The vulnerability exists in the content manager WYSIWYG preview component, which fails to strip script tags from rich text. An Author-role user can store malicious script tags that execute in an Editor or Super Admin's session when the preview pane is ex [truncated]