Skip to content

Strapi

v5.48.0 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 1mo Productivity & Wikis
βœ“ No known CVEs patched
Read the diff β†’ Tool health β†’ What is this tool? β†’
This release patches 1 known CVE

Topics

api cms cms-framework content-management content-management-system customizable
+12 more
web graphql headless-cms jamstack javascript mysql no-code nodejs posgresql rest strapi typescript

Affected surfaces

deps

ReleasePort's take

Moderate signal
editorial:auto 1mo

Patch the vulnerable uuid and qs dependencies to prevent denial‑of‑service attacks.

Why it matters: Severityβ€―90 security issue in uuid and qs; patch immediately to avoid DoS.

Summary

AI summary

Broad release touches βš™οΈ Chore, πŸ”₯ Bug fix, ❀️ Thank You, and πŸ’… Enhancement.

Changes in this release

Security Critical

Patch vulnerable uuid and qs dependencies to prevent DoS.

Patch vulnerable uuid and qs dependencies to prevent DoS.

Source: llm_adapter@2026-06-10

Confidence: high

β€”
Feature Medium

Add optional OpenAPI spec route for API documentation.

Add optional OpenAPI spec route for API documentation.

Source: llm_adapter@2026-06-10

Confidence: high

β€”
Feature Medium

Gate OpenAPI endpoint access via configuration settings.

Gate OpenAPI endpoint access via configuration settings.

Source: llm_adapter@2026-06-10

Confidence: high

β€”
Dependency Low

Bump axios from 1.16.1 to 1.17.0.

Bump axios from 1.16.1 to 1.17.0.

Source: llm_adapter@2026-06-10

Confidence: high

β€”
Bugfix Medium

Upload returns unsigned URL when updating media info.

Upload returns unsigned URL when updating media info.

Source: llm_adapter@2026-06-10

Confidence: high

β€”
Bugfix Medium

Widgets display error when role lacks access to mainfield of content‑type.

Widgets display error when role lacks access to mainfield of content‑type.

Source: llm_adapter@2026-06-10

Confidence: high

β€”
Bugfix Medium

Admin fetch client returns empty object for empty JSON body.

Admin fetch client returns empty object for empty JSON body.

Source: llm_adapter@2026-06-10

Confidence: high

β€”
Bugfix Medium

Build process now supports explicit install‑deps argument.

Build process now supports explicit install‑deps argument.

Source: llm_adapter@2026-06-10

Confidence: high

β€”
Bugfix Medium

Restore allowed path‑filter pin in CI workflow.

Restore allowed path‑filter pin in CI workflow.

Source: llm_adapter@2026-06-10

Confidence: high

β€”
Bugfix Medium

Validate numeric inputs before performing database unique checks.

Validate numeric inputs before performing database unique checks.

Source: llm_adapter@2026-06-10

Confidence: low

β€”
Full changelog

5.48.0 (2026-06-10)

πŸš€ New feature

  • add optional openapi spec route (#26239)
  • openapi: gate endpoint access with config (#26574)

πŸ”₯ Bug fix

  • upload returns unsigned URL on update media info (#25195)
  • widgets show error when role has no access to mainfield of ct (#26537)
  • admin: return empty object for empty json body in fetch client (#26277)
  • build: build does not run install; add install-deps arg (#26483)
  • ci: run build:size as full command for compressed-size-action v3 (#26556)
  • ci: restore allowed paths-filter pin (#26575)
  • content-manager: use ReadonlyArray for layout prop and fix Repeatable test fixture (#26522)
  • content-manager: raise z-index of code block language selector (#25010, #26324)
  • core: validate numeric inputs before DB unique checks (#26101)
  • database: restore join-table relation sort order in components (#26553)
  • database: avoid double finalising completed transactions (#26122)
  • upload: folder navigation bugs in Media Library (#26515)
  • upload: preserve animation frames in GIF and WebP images (#26126)
  • utils: ignore empty sort when building orderBy (#26427)

πŸ“š Documentation Changes

  • openapi: add contributor documentation (#26410)

βš™οΈ Chore

  • remove experimental-dev example app (#26552)
  • update .gitignore for AI tooling directories (#26526)
  • deps: bump axios from 1.16.1 to 1.17.0 (#26539)
  • deps: bump the testing-library group across 1 directory with 2 updates (#26506)
  • deps: bump actions/setup-node from 4 to 6 (#26496)
  • deps: bump actions/stale from 10 to 10.2.0 (#26497)
  • deps: bump preactjs/compressed-size-action from 2 to 3 (#26498)
  • deps: resolve vulnerable transitive deps via lockfile dedupe and resolutions (#26540)
  • deps: bump cheerio from 1.0.0 to 1.2.0 (#26569)
  • deps: bump dorny/paths-filter from 3.0.3 to 4.0.1 (#26566)
  • deps: bump actions/download-artifact from 4.3.0 to 8.0.1 (#26564)
  • deps-dev: bump the eslint group across 1 directory with 10 updates (#26500)
  • deps-dev: bump @types/delegates from 1.0.0 to 1.0.3 (#26570)
  • deps-dev: bump the nx group across 1 directory with 2 updates (#26502)
  • repo: skip change freeze ownership check when freeze disabled (#26474)

πŸ’… Enhancement

  • core/core: rounded thin borders for startup banner (#26273)
  • graphql: use discriminated unions instead of unsafe type casting (#25913)
  • upgrade: unhide and document upgrade to command (#26446)

🚨 Security

  • deps: patch uuid (GHSA-w5hq-g745-h8pq) and qs DoS advisories (9aef801f35)
  • deps: scope uuid/qs resolutions to affected descriptors (38b6831652)

❀️ Thank You

  • Andrei L @unrevised6419
  • Andrei Varapayeu @thisavoropaev
  • Arav Menon @Arav-Menon
  • AurΓ©lien GEORGET
  • Ben Irvin
  • Dante Calderon @dantehemerson
  • Jamie Howard @jhoward1994
  • Maksim Zhukau @MaksZhukov
  • mathildeleg @mathildeleg
  • Nico AndrΓ©

Security Fixes

  • Patch uuid (GHSA-w5hq-g745-h8pq) and qs DoS advisories via dependency resolution

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Strapi

Get notified when new releases ship.

Sign up free

About Strapi

The most advanced open-source Content Management Framework (headless-CMS) to build powerful API with no effort.

All releases β†’

Related context

Earlier breaking changes

  • v5.50.2 Reject 'status' attribute when draftAndPublish is enabled, logging a warning instead of failing boot.
  • v5.46.0 Strapi v4 marked as End of Life

Beta — feedback welcome: [email protected]