Skip to content

KeystoneJS

Developer Productivity

A developer‑focused, extensible content management system that generates a GraphQL API and admin UI from your schema definition.

TypeScript Latest 2026-07-21 · 6d ago Security brief →

Features

  • Generates a powerful GraphQL API automatically from your data schema
  • Provides a beautiful, self‑hosted management UI for content and data
  • Zero boilerplate – start with the `create-keystone-app` CLI to scaffold projects instantly

Recent releases

View all 2 releases →
Review required
2026-07-21 Breaking risk
Breaking upgrade

Next 15 + React 19 upgrades

2026-03-19 Security relevant
Security fixes
  • CVE-2026-33326 — {field}.isFilterable access control could be bypassed in `findMany` queries by passing a `cursor`, allowing existence confirmation of protected records.
Full changelog

The following packages have been updated

@keystone-6/[email protected]

Bug Fixes

  • [core] Fix isFilterable bypass via cursor parameter in findMany query (#9790) @n0wsh

:rotating_light: Security Updates

We have identified and fixed 1 security vulnerability

  • CVE-2026-33326 - {field}.isFilterable access control could be bypassed in findMany queries by passing a cursor. This could be used to confirm the existence of records by protected field values.

:eyes: Review

See https://github.com/keystonejs/keystone/compare/2025-05-06...2026-03-19 to compare with our previous release.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
9,917
Forks
1,263
Languages
TypeScript JavaScript HTML
Downloads/week
6,880 ↑3%
NPM Maintainers
4
Contributors
100
TypeScript
Types included ✓

Install & Platforms

Install via
npm

Community & Support

Beta — feedback welcome: [email protected]