Skip to content

docs: add Strapi case study #373

@sonukapoor

Description

@sonukapoor

Add a full case study for Strapi (strapi/strapi) documenting findings from a CVE Lite CLI scan of its yarn.lock.

Key narratives:

  • sanitize-html critical XSS with no fix — same vulnerability found in Ghost, connecting two major CMS platforms
  • Direct vs transitive split: lodash and minimatch are directly fixable; criticals run through transitive chains
  • html-minifier with no fix (same as Ghost)
  • 27 findings across a Yarn Classic lockfile

Follows the standard case study template. Part of the ongoing real-world validation series.

Metadata

Metadata

Assignees

Labels

documentationImprovements or additions to documentation

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions