Strapi is an open source headless content management system. In Strapi versions prior to 5.33.3, changing or resetting a user's password did not invalidate the user's existing refresh-token sessions by default. The refresh-token invalidation step in the users-permissions and admin authentication controllers was conditional on a caller-supplied deviceId. When a password change or reset request did not include a deviceId, no refresh tokens were revoked, leaving every prior session active. An attacker who had previously obtained a refresh token could continue minting new access tokens after the legitimate user reset their password, allowing persistent unauthorized access for the lifetime of the refresh token (up to 30 days by default). Rotating credentials no longer terminated an active attacker session, defeating password reset as a containment measure. The patch in version 5.33.3 invalidates all refresh tokens associated with the user on every password change and password reset, regardless of whether a deviceId is supplied. A new device-scoped session is then issued to the caller as part of the response.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
AFTERLIFE is a Python 3.11+ local red/blue authentication-security lab modeling CVE-2026-22706 in Strapi <=5.33.2: revocation after a password reset or other security-critical account change is incorrectly conditional on caller-controlled `device_id`. The repository is not a general-purpose exploit against remote systems; it contains an intentionally vulnerable FastAPI application, deterministic in-process proof-of-concept scenarios, telemetry, a detector rule pack, a state audit, a read-only forensic console, generated reports, and extensive regression tests. The core vulnerable behavior is in `app/auth.py:_revoke_for_security_change`. In vulnerable mode, omission of `device_id` lets a password/security-change endpoint return success and issue a legitimate replacement session without recording the per-user `credentials_valid_after` revocation watermark or revoking the old credential lineage. An attacker who already stole a refresh token can then call `POST /refresh`, receive newly minted credentials descended from the old lineage, and access protected routes. A caller-provided device ID activates only device-scoped revocation, which remains incomplete for multi-device accounts. Fixed mode always records a watermark and revokes all existing lineages before issuing a replacement session. `app/` implements FastAPI routes, server-side SQLite credential state, JWT issuance/validation, token lineage tracking, and JSONL telemetry. `scripts/lab.py` is the main POC harness and uses FastAPI TestClient with a pinned/rewindable lab clock, so it normally opens no network port. `scripts/scenarios.py` exercises nine scenarios in both modes. `detector/` is a standalone read-only JSONL analyzer: AFTERLIFE-001 detects accepted post-change credential lineages, AFTERLIFE-003 detects incomplete containment at the security-change event, and AFTERLIFE-002 detects refresh-token reuse/theft. `detector/naive.py` intentionally demonstrates why comparing a credential's own issuance time misses a freshly minted token whose lineage predates the change. `console/` serves a read-only visualization on loopback, while `docs/`, `evidence/`, and `report/` contain reproducible generated artifacts. Both API and console launchers explicitly refuse non-loopback bind addresses. Nonetheless, the project is deliberately unsafe to deploy: it returns bearer credentials in response bodies, includes an unauthenticated `/lab/audit` endpoint, exposes credential-state inspection, lacks TLS and common production controls, and permits lab role changes. The default mode is fixed; vulnerable mode must be explicitly selected.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.