Package compatibility
Strapi
Node.js requirements from npm Registry (engines.node) for the @strapi/strapi package. This is not a lifecycle software page.
Compatibility is derived from the declared Node.js version requirement (npm engines.node). CompatHub does not independently test every combination.
Version lines
Each line reflects a declared engines.node tip. Requirement changes across tips appear as separate lines when present.
Known vulnerabilities
Recent OSV.dev advisories mapped to this product. CVSS/CWE from NVD and known-exploited status from CISA KEV when available. CompatHub is not the original vulnerability authority.
- CVE-2026-27886GHSA-rjg2-95x7-8qmx
Strapi may leak sensitive data via relational filtering due to lack of query sanitization
- Affected:
- >=4.0.0,<5.37.0
- Fixed in:
- 5.37.0
- Source:
- OSV source · Advisory
- CVE-2025-3930GHSA-4r8w-3jww-m2rp
Strapi is vulnerable to Insufficient Session Expiration
- Affected:
- <5.24.1
- Fixed in:
- 5.24.1
- Source:
- OSV source · Advisory
- CVE-2024-37818GHSA-p9ff-j98v-p435
Strapi Server-Side Request Forgery (SSRF)
- Affected:
- unknown
- Fixed in:
- unknown
- Source:
- OSV source · Advisory
- CVE-2023-39345GHSA-gc7p-j5xm-xxh2
Unauthorized Access to Private Fields in User Registration API
- Affected:
- >=4.0.0,<4.13.1
- Fixed in:
- 4.13.1
- Source:
- OSV source · Advisory
- CVE-2023-34093GHSA-chmr-rg2f-9jmf
Making all attributes on a content-type public without noticing it
- Affected:
- <4.10.8
- Fixed in:
- 4.10.8
- Source:
- OSV source · Advisory
- CVE-2023-22894GHSA-jjqf-j4w7-92w8
Strapi leaking sensitive user information by filtering on private fields
- Affected:
- >=3.2.1,<4.8.0
- Fixed in:
- 4.8.0
- Source:
- OSV source · Advisory
- CVE-2022-31367GHSA-4phg-hpqm-c3j4
Strapi mishandles hidden attributes within admin API responses
- Affected:
- >=4.0.0-next.0,<4.1.10
- Fixed in:
- 4.1.10
- Source:
- OSV source · Advisory
- CVE-2022-32114GHSA-4vm8-j95f-j6v5
Strapi 4.1.12 Cross-site Scripting via crafted file
- Affected:
- <=4.1.12
- Source:
- OSV source · Advisory
- CVE-2022-30618GHSA-vgj7-895j-gpr6
Improper Removal of Sensitive Information Before Storage or Transfer in Strapi
- Affected:
- <4.1.9
- Fixed in:
- 4.1.9
- Source:
- OSV source · Advisory
- CVE-2022-30617GHSA-f6fm-r26q-p747
Improper Removal of Sensitive Information Before Storage or Transfer in Strapi
- Affected:
- <4.0.0-beta.15
- Fixed in:
- 4.0.0-beta.15
- Source:
- OSV source · Advisory
- CVE-2021-46440GHSA-85vg-grr5-pw42
Insecure password handling vulnerability in Strapi
- Affected:
- >=4.0.0,<4.1.5
- Fixed in:
- 4.1.5
- Source:
- OSV source · Advisory
