This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+12 more
Affected surfaces
ReleasePort's take
Moderate signalPatch the vulnerable uuid and qs dependencies to prevent denialβofβservice attacks.
Why it matters: Severityβ―90 security issue in uuid and qs; patch immediately to avoid DoS.
Summary
AI summaryBroad release touches βοΈ Chore, π₯ Bug fix, β€οΈ Thank You, and π Enhancement.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Patch vulnerable uuid and qs dependencies to prevent DoS. Patch vulnerable uuid and qs dependencies to prevent DoS. Source: llm_adapter@2026-06-10 Confidence: high |
β |
| Feature | Medium |
Add optional OpenAPI spec route for API documentation. Add optional OpenAPI spec route for API documentation. Source: llm_adapter@2026-06-10 Confidence: high |
β |
| Feature | Medium |
Gate OpenAPI endpoint access via configuration settings. Gate OpenAPI endpoint access via configuration settings. Source: llm_adapter@2026-06-10 Confidence: high |
β |
| Dependency | Low |
Bump axios from 1.16.1 to 1.17.0. Bump axios from 1.16.1 to 1.17.0. Source: llm_adapter@2026-06-10 Confidence: high |
β |
| Bugfix | Medium |
Upload returns unsigned URL when updating media info. Upload returns unsigned URL when updating media info. Source: llm_adapter@2026-06-10 Confidence: high |
β |
| Bugfix | Medium |
Widgets display error when role lacks access to mainfield of contentβtype. Widgets display error when role lacks access to mainfield of contentβtype. Source: llm_adapter@2026-06-10 Confidence: high |
β |
| Bugfix | Medium |
Admin fetch client returns empty object for empty JSON body. Admin fetch client returns empty object for empty JSON body. Source: llm_adapter@2026-06-10 Confidence: high |
β |
| Bugfix | Medium |
Build process now supports explicit installβdeps argument. Build process now supports explicit installβdeps argument. Source: llm_adapter@2026-06-10 Confidence: high |
β |
| Bugfix | Medium |
Restore allowed pathβfilter pin in CI workflow. Restore allowed pathβfilter pin in CI workflow. Source: llm_adapter@2026-06-10 Confidence: high |
β |
| Bugfix | Medium |
Validate numeric inputs before performing database unique checks. Validate numeric inputs before performing database unique checks. Source: llm_adapter@2026-06-10 Confidence: low |
β |
Full changelog
5.48.0 (2026-06-10)
π New feature
π₯ Bug fix
- upload returns unsigned URL on update media info (#25195)
- widgets show error when role has no access to mainfield of ct (#26537)
- admin: return empty object for empty json body in fetch client (#26277)
- build: build does not run install; add install-deps arg (#26483)
- ci: run build:size as full command for compressed-size-action v3 (#26556)
- ci: restore allowed paths-filter pin (#26575)
- content-manager: use ReadonlyArray for layout prop and fix Repeatable test fixture (#26522)
- content-manager: raise z-index of code block language selector (#25010, #26324)
- core: validate numeric inputs before DB unique checks (#26101)
- database: restore join-table relation sort order in components (#26553)
- database: avoid double finalising completed transactions (#26122)
- upload: folder navigation bugs in Media Library (#26515)
- upload: preserve animation frames in GIF and WebP images (#26126)
- utils: ignore empty sort when building orderBy (#26427)
π Documentation Changes
- openapi: add contributor documentation (#26410)
βοΈ Chore
- remove experimental-dev example app (#26552)
- update .gitignore for AI tooling directories (#26526)
- deps: bump axios from 1.16.1 to 1.17.0 (#26539)
- deps: bump the testing-library group across 1 directory with 2 updates (#26506)
- deps: bump actions/setup-node from 4 to 6 (#26496)
- deps: bump actions/stale from 10 to 10.2.0 (#26497)
- deps: bump preactjs/compressed-size-action from 2 to 3 (#26498)
- deps: resolve vulnerable transitive deps via lockfile dedupe and resolutions (#26540)
- deps: bump cheerio from 1.0.0 to 1.2.0 (#26569)
- deps: bump dorny/paths-filter from 3.0.3 to 4.0.1 (#26566)
- deps: bump actions/download-artifact from 4.3.0 to 8.0.1 (#26564)
- deps-dev: bump the eslint group across 1 directory with 10 updates (#26500)
- deps-dev: bump @types/delegates from 1.0.0 to 1.0.3 (#26570)
- deps-dev: bump the nx group across 1 directory with 2 updates (#26502)
- repo: skip change freeze ownership check when freeze disabled (#26474)
π Enhancement
- core/core: rounded thin borders for startup banner (#26273)
- graphql: use discriminated unions instead of unsafe type casting (#25913)
- upgrade: unhide and document upgrade to command (#26446)
π¨ Security
- deps: patch uuid (GHSA-w5hq-g745-h8pq) and qs DoS advisories (9aef801f35)
- deps: scope uuid/qs resolutions to affected descriptors (38b6831652)
β€οΈ Thank You
- Andrei L @unrevised6419
- Andrei Varapayeu @thisavoropaev
- Arav Menon @Arav-Menon
- AurΓ©lien GEORGET
- Ben Irvin
- Dante Calderon @dantehemerson
- Jamie Howard @jhoward1994
- Maksim Zhukau @MaksZhukov
- mathildeleg @mathildeleg
- Nico AndrΓ©
Security Fixes
- Patch uuid (GHSA-w5hq-g745-h8pq) and qs DoS advisories via dependency resolution
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Strapi
The most advanced open-source Content Management Framework (headless-CMS) to build powerful API with no effort.
Beta — feedback welcome: [email protected]