Skip to content

Strapi

v4.26.2 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

Published 1mo Productivity & Wikis
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Topics

api cms cms-framework content-management content-management-system customizable
+12 more
web graphql headless-cms jamstack javascript mysql no-code nodejs posgresql rest strapi typescript

Affected surfaces

auth deps

ReleasePort's take

Moderate signal
editorial:auto 1mo

The release fixes a critical vulnerability that exposed sensitive data through insufficient query sanitization.

Why it matters: Severity score of 90 indicates a critical flaw affecting relational filtering queries; patch immediately to prevent data leakage.

Summary

AI summary

Updates Compatibility, End-Of-Life, and https://github.com/strapi/strapi/security/advisories/GHSA-rjg2-95x7-8qmx across a mixed release.

Changes in this release

Security Critical

Fixes critical vulnerability exposing sensitive data via insufficient query sanitization.

Fixes critical vulnerability exposing sensitive data via insufficient query sanitization.

Source: llm_adapter@2026-06-09

Confidence: high

Dependency Low

Upgraded `tar` to version 7 for security fixes.

Upgraded `tar` to version 7 for security fixes.

Source: llm_adapter@2026-06-09

Confidence: high

Dependency Low

Applied Strapi v4 dependency security and maintenance updates.

Applied Strapi v4 dependency security and maintenance updates.

Source: llm_adapter@2026-06-09

Confidence: high

Dependency Low

Added Node.js 22 support for Strapi v4.

Added Node.js 22 support for Strapi v4.

Source: llm_adapter@2026-06-09

Confidence: low

Bugfix Medium

Enforces unique admin email validation when updating authenticated user profile.

Enforces unique admin email validation when updating authenticated user profile.

Source: llm_adapter@2026-06-09

Confidence: high

Full changelog

:warning: Note: This is the final Strapi 4 release :warning:

No further updates to Strapi 4 will be published, this release serves as the final version of Strapi 4 which is considered EOL (End-Of-Life) as of April 30th, 2026. All Strapi users should migrate to Strapi 5: https://docs.strapi.io/cms/migration/v4-to-v5/introduction-and-faq

Also please note, this does include Strapi Customers as well. Strapi Cloud will still continue to function with Strapi 4 but that may be subject change in the near future without warning.

What's Changed

Security

  • Fixed a critical vulnerability where relational filtering could expose sensitive data through insufficient query sanitization. See GHSA-rjg2-95x7-8qmx / CVE-2026-27886.
  • Upgraded tar to v7 to address security warnings.
  • Applied v4 dependency security and maintenance updates.

Fixes

  • Enforced unique admin email validation when updating the authenticated user profile.

Compatibility

  • Added Node.js 22 support for Strapi v4.

Full Changelog: https://github.com/strapi/strapi/compare/v4.26.1...v4.26.2

Breaking Changes

  • Strapi 4 is marked End‑Of‑Life; no further updates will be published after April 30 2026. Migration to Strapi 5 is required.

Security Fixes

  • GHSA-rjg2-95x7-8qmx / CVE-2026-27886 – Fixed critical vulnerability where relational filtering exposed sensitive data due to insufficient query sanitization.
  • dep: Upgraded `tar` to v7 to address security warnings.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Strapi

Get notified when new releases ship.

Sign up free

About Strapi

The most advanced open-source Content Management Framework (headless-CMS) to build powerful API with no effort.

All releases →

Related context

Earlier breaking changes

  • v5.50.2 Reject 'status' attribute when draftAndPublish is enabled, logging a warning instead of failing boot.
  • v5.46.0 Strapi v4 marked as End of Life

Beta — feedback welcome: [email protected]