This release includes 2 security fixes for security teams reviewing exposed deployments.
Topics
+12 more
Affected surfaces
ReleasePort's take
Moderate signalThe release fixes a critical vulnerability that exposed sensitive data through insufficient query sanitization.
Why it matters: Severity score of 90 indicates a critical flaw affecting relational filtering queries; patch immediately to prevent data leakage.
Summary
AI summaryUpdates Compatibility, End-Of-Life, and https://github.com/strapi/strapi/security/advisories/GHSA-rjg2-95x7-8qmx across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Fixes critical vulnerability exposing sensitive data via insufficient query sanitization. Fixes critical vulnerability exposing sensitive data via insufficient query sanitization. Source: llm_adapter@2026-06-09 Confidence: high |
— |
| Dependency | Low |
Upgraded `tar` to version 7 for security fixes. Upgraded `tar` to version 7 for security fixes. Source: llm_adapter@2026-06-09 Confidence: high |
— |
| Dependency | Low |
Applied Strapi v4 dependency security and maintenance updates. Applied Strapi v4 dependency security and maintenance updates. Source: llm_adapter@2026-06-09 Confidence: high |
— |
| Dependency | Low |
Added Node.js 22 support for Strapi v4. Added Node.js 22 support for Strapi v4. Source: llm_adapter@2026-06-09 Confidence: low |
— |
| Bugfix | Medium |
Enforces unique admin email validation when updating authenticated user profile. Enforces unique admin email validation when updating authenticated user profile. Source: llm_adapter@2026-06-09 Confidence: high |
— |
Full changelog
:warning: Note: This is the final Strapi 4 release :warning:
No further updates to Strapi 4 will be published, this release serves as the final version of Strapi 4 which is considered EOL (End-Of-Life) as of April 30th, 2026. All Strapi users should migrate to Strapi 5: https://docs.strapi.io/cms/migration/v4-to-v5/introduction-and-faq
Also please note, this does include Strapi Customers as well. Strapi Cloud will still continue to function with Strapi 4 but that may be subject change in the near future without warning.
What's Changed
Security
- Fixed a critical vulnerability where relational filtering could expose sensitive data through insufficient query sanitization. See GHSA-rjg2-95x7-8qmx / CVE-2026-27886.
- Upgraded
tarto v7 to address security warnings. - Applied v4 dependency security and maintenance updates.
Fixes
- Enforced unique admin email validation when updating the authenticated user profile.
Compatibility
- Added Node.js 22 support for Strapi v4.
Full Changelog: https://github.com/strapi/strapi/compare/v4.26.1...v4.26.2
Breaking Changes
- Strapi 4 is marked End‑Of‑Life; no further updates will be published after April 30 2026. Migration to Strapi 5 is required.
Security Fixes
- GHSA-rjg2-95x7-8qmx / CVE-2026-27886 – Fixed critical vulnerability where relational filtering exposed sensitive data due to insufficient query sanitization.
- dep: Upgraded `tar` to v7 to address security warnings.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Strapi
The most advanced open-source Content Management Framework (headless-CMS) to build powerful API with no effort.
Beta — feedback welcome: [email protected]