Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-22599 — Python PoC and Docker lab for CVE-2026-22599, an authenticated SQL injection in Strapi's Content-Type Builder write API via Knex raw defaultTo. | Kitploit
Tools/GitHubGitHub/abraxas/cve-2026-22599
Vulnerability AnalysisExploitationWeb Application ExploitationSecurity VirtualizationWeb SecurityPenetration TestingDatabase SecurityLabs & Practice
GitHubabraxas/cve-2026-22599

CVE-2026-22599

Python PoC and Docker lab for CVE-2026-22599, an authenticated SQL injection in Strapi's Content-Type Builder write API via Knex raw defaultTo.

131 day agoNot yet reviewed
View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Abraxas Labs - CVE-2026-22599

abraxaslabs.tech  ·  github.com/abraxas  ·  @abraxas_null  ·  [email protected]  ·  CVE-2026-22599

CVE-2026-22599

Strapi 5.33.1 - Strapi

I am @abraxas_null. Loopback lab. The client is CVE-2026-22599-Abraxas-Labs.py.

Content-Type Builder write API database-query injection. Yup validates but does not strip unknown column.defaultTo. Schema builder merges [value, { isRaw: true }] into Knex defaultTo(raw()). Fixed in 5.33.2 / 4.26.1 by hiding CTB write APIs in production.

CVECVE-2026-22599 · CVE.org
CWECWE-89
CVSSCritical: 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
ProductStrapi
Affectedall versions through 5.33.1 (inclusive)
Patched5.33.2 / 4.26.1 and later
Authauthenticated
LicenseGNU Affero GPL v3.0
Lab127.0.0.1 only

What an attacker can do

Authenticated administrator JWT. POST /content-type-builder/content-types with a raw DEFAULT expression. Next insert on that type uses attacker SQL. Lab oracle is GHSA22599-WITNESS on a new labitem row, not a shell.


How I found it

I mapped createColumn spreading attribute.column over defaultTo, then isRaw calling knex raw() unsanitized. Stood up Strapi 5.33.1, registered admin, posted the content type, inserted a row.

Fail-controls already in the lab: eval/base64/system is not the witness; a reverse shell is not the witness; 5.33.2 must not honor the raw tuple.


The lab

Port 18098. Strapi 5.33.1. Administrator JWT. CTB write API reachable (pre-patch: also production). ./run.sh.

  • lab/Dockerfile
  • lab/docker-compose.yml
  • lab/run.sh

Target only 127.0.0.1:18098 (or the loopback you bound).

cd lab
docker compose up --force-recreate
python3 ../CVE-2026-22599-Abraxas-Labs.py

Witness: content-manager entry JSON contains GHSA22599-WITNESS.

Ways to lose without learning anything:

  • eval / base64 / system payload
  • reverse shell
  • patched 5.33.2

The fix

Update Strapi to 5.33.2 / 4.26.1 or newer. Re-run CVE-2026-22599-Abraxas-Labs.py against the patched build: the raw DEFAULT must not land.


References

  • CVE-2026-22599 · NVD

  • CVE-2026-22599 · CVE.org

  • github.com/strapi/strapi/security/advisories/GHSA-3xcq-8mjw-h6mx

  • strapi.io/blog/security-disclosure-of-vulnerabilities-cve-2025-64526-cve-2026-22599-cve-2026-22706-cve-2026-22707-and-cve-2026-27886

  • Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null


License

GNU Affero GPL v3.0. See LICENSE.


The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.

abraxaslabs.tech · github.com/abraxas · @abraxas_null

Download Tool