CVE-2026-22707: Strapi Upload Plugin MIME Validation Bypass via Content API
- CVE: CVE-2026-22707
- CVSS v3.1 Vector:
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N(5.3 — Medium) - Affected Versions:
@strapi/upload<=5.33.2 - How to Patch: Immediately update your Strapi to >=5.33.3
References
Code Behaviors & Features
Detect and mitigate CVE-2026-22707 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →