Strapi is an open source headless content management system. In versions on the 4.x branch prior to 4.26.1 and on the 5.x branch prior to 5.33.2, a database-query injection vulnerability existed in the Strapi Content-Type Builder write API. An authenticated administrator could inject arbitrary database statements through the column.defaultTo attribute when creating or modifying a content type. Setting defaultTo as a tuple [value, { isRaw: true }] caused the value to be passed directly into Knex's db.connection.raw() during schema migration without sanitization, allowing arbitrary statement execution at the database layer. Depending on the database engine, this enabled arbitrary file read via database utility functions, denial of service via forced server crash on schema-migration error, and on engines that permit external program execution, remote code execution against the database server. The patch in versions 4.26.1 and 5.33.2 addresses this by restricting all Content-Type Builder write APIs to development mode only. Production deployments running v5.33.2 or later return 404 for requests against /content-type-builder/content-types and related endpoints, removing the network-reachable attack surface entirely.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This seven-file repository is an authenticated proof of concept for CVE-2026-22599, a reported Strapi Content-Type Builder SQL-injection issue. Its primary artifact, `CVE-2026-22599-Abraxas-Labs.py`, is a Python script that authenticates as an administrator, submits a content-type definition containing a `column.defaultTo` value marked `isRaw`, waits for Strapi's schema reload, and creates or lists a `labitem` record to verify the injected `GHSA22599-WITNESS` default expression. The demonstrated impact is unsafe attacker-controlled SQL expression handling through Knex raw-query construction, not direct command execution; no reverse shell, downloader, persistence mechanism, or external command-and-control endpoint is present. The repository also contains a README advisory and reproduction guidance, AGPLv3 license, and a self-contained Docker lab. `lab/Dockerfile` builds a development Strapi 5.33.1 installation with SQLite, while `lab/docker-compose.yml` exposes it only on `127.0.0.1:18098`. `lab/run.sh` starts the lab and polls `/admin`. Notably, that shell wrapper references `poc.py`, but no such file exists in the supplied seven-file tree; the actual PoC is named `CVE-2026-22599-Abraxas-Labs.py`. The README separately documents port 8088, so the supplied lab wrapper and documentation require reconciliation before direct use.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.