{"id":"GHSA-495j-h493-42q2","summary":"Strapi Allows Unauthorized Access to Private Fields via parms.lookup","details":"### Summary\nIt's possible to access any private fields by filtering through the lookup parameters\n\n### Details\n\nUsing the new lookup operator provided by the document service in Strapi 5, it is not properly sanitizing this query operator for private fields.\n\n### PoC\n\n1. Create a strapi app.\n2. Create a content-type\n3. In the content-type you make a new entry\n4. Go back to the list view\n4. Add `&lookup[updatedBy][password][$startsWith]=$2` to the end of your url (All passwords start with $2) see that all entries are still there\n6. Add `&lookup[updatedBy][password][$startsWith]=$3` see the entry disappear proving that the search above works\n\n### Impact\n\nAn attacker can perform filtering attacks on everything related to the object, including admin passwords and reset-tokens. This means that they can gain full access to the strapi instance.","aliases":["CVE-2024-56143"],"modified":"2025-10-16T20:42:12Z","published":"2025-10-16T18:22:40Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2025-10-16T18:22:40Z","nvd_published_at":"2025-10-16T16:15:36Z","cwe_ids":["CWE-639"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/strapi/strapi/security/advisories/GHSA-495j-h493-42q2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-56143"},{"type":"WEB","url":"https://github.com/strapi/strapi/commit/0c6e0953ae1e62afae9329de7ae6d6a5e21b95b8"},{"type":"PACKAGE","url":"https://github.com/strapi/strapi"}],"affected":[{"package":{"name":"@strapi/core","ecosystem":"npm","purl":"pkg:npm/%40strapi/core"},"ranges":[{"type":"SEMVER","events":[{"introduced":"5.0.0"},{"fixed":"5.5.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-495j-h493-42q2/GHSA-495j-h493-42q2.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"}]}