Miggo Logo

CVE-2025-53092: Strapi core vulnerable to sensitive data exposure via CORS misconfiguration

6.5

CVSS Score
3.1

Basic Information

EPSS Score
-
Published
10/16/2025
Updated
10/16/2025
KEV Status
No
Technology
TechnologyJavaScript

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Package NameEcosystemVulnerable VersionsFirst Patched Version
@strapi/corenpm< 5.20.05.20.0

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

### Summ*ry * *ORS mis*on*i*ur*tion vuln*r**ility *xists in ****ult inst*ll*tions o* Str*pi w**r* *tt**k*r-*ontroll** ori*ins *r* improp*rly r**l**t** in *PI r*spons*s. ### T***ni**l **t*ils *y ****ult, Str*pi r**l**ts t** v*lu* o* t** Ori*in ****

Reasoning

No *n*lysis *v*il**l*