Status: KEV
| Advisory ID: CVE-2023-22894
Key Details
| CVE | CVE-2023-22894 |
| Vulnerability Name | Strapi Cleartext Storage of Sensitive Information Vulnerability |
| Affected products | Strapi Strapi |
| Exploitation status | Listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation. |
| Classified as | CWE-312 (Cleartext Storage of Sensitive Information) |
| KEV listing | Added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-10-08. |
| Federal remediation deadline | 2026-10-11 (CISA KEV, Binding Operational Directive). |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
Strapi contains a cleartext storage of sensitive information vulnerability that could allow attackers with access to the admin panel to discover sensitive user details via the query filter. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. This vulnerability can be chained with CVE-2023-22621 to achieve remote code execution. (CISA)
What to Do
Monitor Strapi's web page for any future patch releases.
References
KEV Required Action