
Python PoC and Docker lab for CVE-2026-22599, an authenticated SQL injection in Strapi's Content-Type Builder write API via Knex raw defaultTo.
abraxaslabs.tech · github.com/abraxas · @abraxas_null · [email protected] · CVE-2026-22599
Strapi 5.33.1 - Strapi
I am @abraxas_null. Loopback lab. The client is CVE-2026-22599-Abraxas-Labs.py.
Content-Type Builder write API database-query injection. Yup validates but does not strip unknown column.defaultTo. Schema builder merges [value, { isRaw: true }] into Knex defaultTo(raw()). Fixed in 5.33.2 / 4.26.1 by hiding CTB write APIs in production.
| CVE | CVE-2026-22599 · CVE.org |
| CWE | CWE-89 |
| CVSS | Critical: 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N |
| Product | Strapi |
| Affected | all versions through 5.33.1 (inclusive) |
| Patched | 5.33.2 / 4.26.1 and later |
| Auth | authenticated |
| License | GNU Affero GPL v3.0 |
| Lab | 127.0.0.1 only |
Authenticated administrator JWT. POST /content-type-builder/content-types with a raw DEFAULT expression. Next insert on that type uses attacker SQL. Lab oracle is GHSA22599-WITNESS on a new labitem row, not a shell.
I mapped createColumn spreading attribute.column over defaultTo, then isRaw calling knex raw() unsanitized. Stood up Strapi 5.33.1, registered admin, posted the content type, inserted a row.
Fail-controls already in the lab: eval/base64/system is not the witness; a reverse shell is not the witness; 5.33.2 must not honor the raw tuple.
Port 18098. Strapi 5.33.1. Administrator JWT. CTB write API reachable (pre-patch: also production). ./run.sh.
Target only 127.0.0.1:18098 (or the loopback you bound).
cd lab
docker compose up --force-recreate
python3 ../CVE-2026-22599-Abraxas-Labs.py
Witness: content-manager entry JSON contains GHSA22599-WITNESS.
Ways to lose without learning anything:
Update Strapi to 5.33.2 / 4.26.1 or newer. Re-run CVE-2026-22599-Abraxas-Labs.py against the patched build: the raw DEFAULT must not land.
github.com/strapi/strapi/security/advisories/GHSA-3xcq-8mjw-h6mx
Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null
GNU Affero GPL v3.0. See LICENSE.
The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.