← All Advisories

CVE-2023-22894: Strapi Cleartext Storage of

Last refreshed2026-10-09

Status: KEV  |  Advisory ID: CVE-2023-22894

Key Details

CVECVE-2023-22894
Vulnerability NameStrapi Cleartext Storage of Sensitive Information Vulnerability
Affected productsStrapi Strapi
Exploitation statusListed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation.
Classified asCWE-312 (Cleartext Storage of Sensitive Information)
KEV listingAdded to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-10-08.
Federal remediation deadline2026-10-11 (CISA KEV, Binding Operational Directive).

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
StrapiStrapi
SubsystemsGeneral OT
SectorsMultiple

What to Know

Strapi contains a cleartext storage of sensitive information vulnerability that could allow attackers with access to the admin panel to discover sensitive user details via the query filter. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. This vulnerability can be chained with CVE-2023-22621 to achieve remote code execution. (CISA)

What to Do

Monitor Strapi's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2023-22894
CVEhttps://www.cve.org/CVERecord?id=CVE-2023-22894

KEV Required Action

FieldValue
KEV Linkhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog
Date Added to KEV2026-10-08
Required Action Due Date2026-10-11
Required ActionApply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.