CVE-2025-53092 MEDIUM

CVE-2025-53092: Strapi core vulnerable to sensitive data exposure via CORS misconfiguration

Vendor Strapi
Product strapi
Weakness CWE-200 · Info exposure
Published October 16, 2025
Last update October 16, 2025

CVSS base score

6.5/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

What the vulnerability does

01Description

Strapi is an open source headless content management system. Strapi versions prior to 5.20.0 contain a CORS misconfiguration vulnerability in default installations. By default, Strapi reflects the value of the Origin header back in the Access-Control-Allow-Origin response header without proper validation or whitelisting. This allows an attacker-controlled site to send credentialed requests to the Strapi backend. An attacker can exploit this by hosting a malicious site on a different origin (e.g., different port) and sending requests with credentials to the Strapi API. The vulnerability is fixed in version 5.20.0. No known workarounds exist.

Key dates

02Disclosure timeline

October 16, 2025 CVE published
October 16, 2025 Record updated