External risk intelligence

Strapi Stored XSS in WYSIWYG Preview Component

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-90561

The vulnerability exists within the Strapi content manager's WYSIWYG preview component, which is part of the administrative interface. While Strapi instances are often internet-facing, this specific issue requires a user with at least an 'Author' role to trigger and targets authenticated administrators, making it less likely to be exploited via the public-facing side of the application.

Cross-site Scripting

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability exists in Strapi's content management system, specifically within the rich text editor's preview function. This issue allows an authenticated user with author privileges to inject malicious scripts that could execute within the sessions of higher-privileged users, potentially leading to account takeover. The primary concern is confirming whether this specific functionality is in use and exposed to such a risk.

  • Malicious scripts can run in privileged user sessions.
  • Impacts administrators through content previews.
  • Confirm relevance and exposure within the environment.

Attack Path

How an attacker could exploit the issue

An attacker with author privileges can inject malicious script tags into rich text fields within Strapi's content manager. When an administrator views the preview of this rich text content, the injected scripts execute within their browser session, potentially leading to account takeover.

  • Requires author role access.
  • Triggered by previewing rich text.
  • Risk of administrative account takeover.

Live Threat

Current exploitation, exposure, and threat context

A stored cross-site scripting vulnerability in the Strapi content manager's WYSIWYG preview component could allow an authenticated 'Author' user to execute arbitrary script code in the browser of an 'Editor' or 'Super Admin' user when they interact with the preview pane. This could potentially lead to account takeover.

  • Stored script tags in rich text fields.
  • Malicious scripts execute in admin session.
  • Account takeover of admin user.

Operational Fix

Recommended remediation, mitigation, and detection steps

Application owners and infrastructure teams are primarily responsible for addressing this stored cross-site scripting vulnerability in Strapi. The first practical step is to identify all Strapi instances, confirm their exposure and criticality, and then locate the accountable owner to plan remediation.

  • Identify Strapi owners and critical instances.
  • Verify WYSIWYG preview component reachability.
  • Plan and coordinate remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Strapi and where does this bug occur?

Strapi is an open-source headless Content Management System used to build APIs and manage website or application content. This vulnerability specifically affects the 'WYSIWYG' (What You See Is What You Get) preview component found within the administrative panel, which users rely on to see how rich text will look before publishing.

What is the nature of CVE-2026-90561?

This is a Stored Cross-Site Scripting (XSS) vulnerability, classified as CWE-79. It occurs because the preview component fails to properly filter out script tags from rich text input. Because the script is 'stored,' it remains in the system and runs automatically whenever an unsuspecting user with higher privileges opens that specific preview.

How does the trigger for this vulnerability work?

An attacker must first have an active 'Author' role to save malicious script tags into a rich text field. The bug is only triggered when a different user—specifically an Editor or Super Admin—actively clicks to view the preview of that content. Merely saving the content or viewing the live site does not trigger the execution; the victim must intentionally interact with the administrative preview feature.

Is my Strapi instance at risk?

According to Halo Surface Signal, this vulnerability is tied to the administrative interface rather than the public-facing side of your site. While your Strapi instance might be internet-facing, the primary risk is internal: you must have an untrusted user with 'Author' access who could target your administrators. Instances without multiple users or those where authors are fully trusted face lower practical risk.

How should I respond to this threat?

Start by identifying all Strapi instances within your environment and checking their versions against the affected range (4.x through 4.26.2, or 5.x before 5.48.1). Once identified, coordinate with the system owners to apply the necessary software updates provided by Strapi. Limit 'Author' role access to trusted individuals until you have successfully updated the platform.

References