CVE-2023-22621: Strapi

High severity, CVSS 7.2. EPSS: 70.6% chance of exploitation in the next 30 days.

Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitrary code on the server. A remote attacker with access to the Strapi admin panel can inject a crafted payload that executes code on the server into an email template that bypasses the validation checks that should prevent code execution.

Affected products

  • Strapi Strapi: from 3.0.0, before 4.5.6 (fixed in 4.5.6)

Published 2023-04-19. Last modified 2026-06-17.