Package compatibility

Strapi

Node.js requirements from npm Registry (engines.node) for the @strapi/strapi package. This is not a lifecycle software page.

Compatibility is derived from the declared Node.js version requirement (npm engines.node). CompatHub does not independently test every combination.

Version lines

Each line reflects a declared engines.node tip. Requirement changes across tips appear as separate lines when present.

Known vulnerabilities

Recent OSV.dev advisories mapped to this product. CVSS/CWE from NVD and known-exploited status from CISA KEV when available. CompatHub is not the original vulnerability authority.

  • CVE-2026-27886GHSA-rjg2-95x7-8qmx

    Strapi may leak sensitive data via relational filtering due to lack of query sanitization

    Affected:
    >=4.0.0,<5.37.0
    Fixed in:
    5.37.0
    Source:
    OSV source · Advisory
  • CVE-2025-3930GHSA-4r8w-3jww-m2rp

    Strapi is vulnerable to Insufficient Session Expiration

    Affected:
    <5.24.1
    Fixed in:
    5.24.1
    Source:
    OSV source · Advisory
  • CVE-2024-37818GHSA-p9ff-j98v-p435

    Strapi Server-Side Request Forgery (SSRF)

    Affected:
    unknown
    Fixed in:
    unknown
    Source:
    OSV source · Advisory
  • CVE-2023-39345GHSA-gc7p-j5xm-xxh2

    Unauthorized Access to Private Fields in User Registration API

    Affected:
    >=4.0.0,<4.13.1
    Fixed in:
    4.13.1
    Source:
    OSV source · Advisory
  • CVE-2023-34093GHSA-chmr-rg2f-9jmf

    Making all attributes on a content-type public without noticing it

    Affected:
    <4.10.8
    Fixed in:
    4.10.8
    Source:
    OSV source · Advisory
  • CVE-2023-22894GHSA-jjqf-j4w7-92w8

    Strapi leaking sensitive user information by filtering on private fields

    Affected:
    >=3.2.1,<4.8.0
    Fixed in:
    4.8.0
    Source:
    OSV source · Advisory
  • CVE-2022-31367GHSA-4phg-hpqm-c3j4

    Strapi mishandles hidden attributes within admin API responses

    Affected:
    >=4.0.0-next.0,<4.1.10
    Fixed in:
    4.1.10
    Source:
    OSV source · Advisory
  • CVE-2022-32114GHSA-4vm8-j95f-j6v5

    Strapi 4.1.12 Cross-site Scripting via crafted file

    Affected:
    <=4.1.12
    Source:
    OSV source · Advisory
  • CVE-2022-30618GHSA-vgj7-895j-gpr6

    Improper Removal of Sensitive Information Before Storage or Transfer in Strapi

    Affected:
    <4.1.9
    Fixed in:
    4.1.9
    Source:
    OSV source · Advisory
  • CVE-2022-30617GHSA-f6fm-r26q-p747

    Improper Removal of Sensitive Information Before Storage or Transfer in Strapi

    Affected:
    <4.0.0-beta.15
    Fixed in:
    4.0.0-beta.15
    Source:
    OSV source · Advisory
  • CVE-2021-46440GHSA-85vg-grr5-pw42

    Insecure password handling vulnerability in Strapi

    Affected:
    >=4.0.0,<4.1.5
    Fixed in:
    4.1.5
    Source:
    OSV source · Advisory
Strapi Node.js Compatibility | CompatHub