CVE-2023-22621: Strapi
High severity, CVSS 7.2. EPSS: 70.6% chance of exploitation in the next 30 days.
Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitrary code on the server. A remote attacker with access to the Strapi admin panel can inject a crafted payload that executes code on the server into an email template that bypasses the validation checks that should prevent code execution.
Affected products
- Strapi Strapi: from 3.0.0, before 4.5.6 (fixed in 4.5.6)
Published 2023-04-19. Last modified 2026-06-17.