CVE-2023-22894 is an information-disclosure vulnerability in Strapi that permits authenticated admin-panel users to filter user records on sensitive private fields and infer their values from API responses. Super administrators can recover password hashes and password reset tokens for all users. Lower-privileged admin-panel accounts, such as Editor or Author, with permission to access API users' usernames and email addresses can obtain sensitive information for all API users, but not other administrator accounts. The CVE description identifies affected releases through 4.5.5, whereas Strapi's advisory identifies versions 3.2.1 through 4.7.9. The issue is an ORM leak through insufficient restriction of queryable private fields and is classified as CWE-312.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Python exploit script (CVE-2023-22894.py) targeting Strapi CMS instances vulnerable to CVE-2023-22894. The script takes a target URL and a public Strapi endpoint as arguments. It then performs a brute-force attack by sending concurrent HTTP GET requests with crafted query parameters to enumerate the bcrypt password hash of a user, and optionally the password reset token. The script uses multithreading to speed up the brute-force process. The main entry point is the Python script itself, which is run from the command line. No hardcoded endpoints are present; the user must supply the vulnerable endpoint. The exploit is operational and demonstrates the vulnerability by extracting sensitive user information from the target Strapi instance.
This repository provides two Python proof-of-concept exploit scripts targeting Strapi CMS versions <=4.7.1, specifically exploiting CVE-2023-22894. The vulnerability allows attackers to leak sensitive information (password hashes and reset tokens) by abusing Strapi's filtering functionality on private fields. - `dump-auth.py` is an authenticated exploit requiring valid Strapi admin credentials. It logs in, retrieves an API token, and then enumerates admin and API user accounts to extract their password hashes and reset tokens via crafted API requests. - `dump-authless.py` is an unauthenticated exploit that targets public API endpoints with a relationship to the User model. It brute-forces and leaks password hashes and, optionally, password reset tokens without needing credentials, provided a suitable endpoint is exposed. Both scripts use multi-threading to speed up the brute-force process. The repository includes a detailed README explaining usage, prerequisites, and the vulnerability context. The main attack vector is network-based, targeting Strapi HTTP API endpoints. The scripts do not provide direct code execution but enable credential theft and account takeover, which can be chained with other vulnerabilities for further exploitation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A cleartext storage vulnerability in Strapi exposing sensitive user details through query filters to an attacker with admin-panel access. CISA added it to KEV following exploitation attributed to Flax Typhoon.
A known exploited vulnerability added to CISA's catalog in connection with the reported Chinese government-linked intrusion activity. The content does not describe its technical mechanism or affected product.
A Strapi vulnerability successfully exploited by the reported hackers. The vendor's advisory gives a wider affected-version range than the joint advisory, making version 4.8.0 the stated remediation threshold.
A Strapi ORM Leak vulnerability that could expose administrator password-reset tokens and enable takeover of a Strapi instance.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.