github.com
https://github.com/strapi/strapi CVE-2024-52588
MEDIUM
Strapi allows Server-Side Request Forgery in Webhook function
Record summary
CVE-2024-52588 has a selected CVSS score of 4.9 (medium).
Description
Strapi is an open-source content management system. Prior to version 4.25.2, inputting a local domain into the Webhooks URL field leads to the application fetching itself, resulting in a server side request forgery (SSRF). This issue has been patched in version 4.25.2.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 29, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
strapiBrowse strapi / strapi | CVE List | < 4.25.2 | affected |
@strapi/adminBrowse npm / @strapi/admin | GitHub Advisory | Before 4.25.2 · Fixed in 4.25.2 | affected |
References
3github.comConfirmation
https://github.com/strapi/strapi/security/advisories/GHSA-v8wj-f5c7-pvxf nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-52588