Strapi Cleartext Storage Flaw (CVE-2023-22894) Added to CISA KEV, Chainable to RCE on EoL Instances
What Happened
CISA has added CVE-2023-22894, a cleartext storage of sensitive information vulnerability in Strapi, to its Known Exploited Vulnerabilities (KEV) catalog, per Strapi's own disclosure. The flaw allows an attacker who already has access to the Strapi admin panel to discover sensitive user details through the query filter. Strapi notes the affected product versions may be end-of-life (EoL) or end-of-service (EoS). CISA's KEV listing marks this as actively exploited, though the item does not specify who is exploiting it or in what campaigns.
Why It Matters
On its own, this is a post-authentication information disclosure bug requiring admin panel access — but Strapi's advisory states it can be chained with CVE-2023-22621 to achieve remote code execution. That chaining potential is what elevates the risk: an attacker who gains or already has limited admin access could escalate to full RCE on the underlying Strapi instance. Organizations running EoL/EoS Strapi deployments are at the highest risk, since no further patches are expected for those versions. Any organization using Strapi as a headless CMS for customer-facing sites or internal content management should treat this as relevant to their attack surface.
What Defenders Should Do Now
- Inventory all Strapi instances and confirm current version against supported releases; if a deployment is EoL/EoS, prioritize migration to a supported version or decommissioning, per Strapi's guidance.
- Review who has admin panel access and audit for unnecessary or stale admin accounts — this vulnerability requires that access as a prerequisite.
- Hunt for unusual query filter usage against user/sensitive-data endpoints in Strapi admin API logs, and for anomalous admin panel logins preceding such queries.
- Because of the chaining risk with CVE-2023-22621, also verify exposure to that vulnerability and apply any available fixes or compensating controls for it.
- Monitor for unexpected outbound connections or process spawning from Strapi hosts, which would indicate successful RCE chaining rather than isolated data exposure.
Developing Intel
This is a same-day KEV addition and details on active exploitation (actors, targets, timeline) have not been published. We will track this item for updates. For the authoritative vendor writeup, see Strapi's security disclosure.