Releases: strapi/strapi
Release list
v5.51.2
5.51.2 (2026-08-05)
🚀 New feature
- content-manager: add optional component screenshots to DZ picker (#26863)
🔥 Bug fix
- use radio roles for accessibility and improve aria attributes (#27139)
- handle i18n conflict and local rights (6519f4d5db)
- admin: interpolate min/max values in validation error messages (#27172)
- admin: pin react-colorful to prevent optimizeDeps include/exclude conflict (#27203)
- content-manager: relation creation discards parent changes (#27081)
- content-manager: relation order changes after saving dynamic-zone components (#27135)
- content-manager: keep document status accurate on mixed-locale batches (#27035)
- core: use configured default pageSize when only page is provided (#27132)
- database: escape LIKE wildcards in filters and use equality for $eqi/$nei (#26476)
- i18n: use fractional temp_key when filling from locale (#26296)
- upload: stream URL imports to disk instead of buffering in memory (#27176)
- upload: keep cursor position while editing asset details fields (CMS-1536) (2c6edbfacb)
- upload: apply asset permissions to media library actions (CMS-434) (e8099188e2)
- upload: keep crop drag tracking on touch devices (CMS-1538) (7807ea83dc)
- upload: keep asset drawer header visible on mobile (CMS-1539) (4edad7ca75)
- upload: media library MVP fixes (7a4012c65a)
📚 Documentation Changes
- add contributor documentation for the MCP server (#27160)
⚙️ Chore
- deps: bump @hono/node-server from 1.19.14 to 1.19.17 (#27166)
- deps: bump postcss from 8.5.14 to 8.5.25 (#27195)
- deps: bump brace-expansion from 1.1.16 to 1.1.18 (#27196)
- deps: bump js-yaml from 3.15.0 to 3.15.1 (#27197)
- deps: bump motion from 12.23.24 to 12.40.0 (#27133)
- deps: bump tar from 7.5.21 to 7.5.22 (#27165)
- deps: bump react-router-dom from 6.30.3 to 6.30.4 (#27134)
- deps: bump undici from 6.27.0 to 6.28.0 (#27164)
- deps: bump axios from 1.18.1 to 1.19.0 (#27198)
- deps: align app-template react-router-dom with admin 6.30.4 (#27210)
- jest: run unit/front tests via nx, drop root jest config and dep (#26701)
- lint: add non-blocking oxlint setup (#26923)
- users-permissions: move server code into server/src (#26105)
💅 Enhancement
- content-type-builder: support required on relation attributes (#27080)
- core: look models up on the registries in getModel (#27143)
- database: reduce per-column work when mapping rows to entities (#27144)
⚠️ Changes to be aware of
Filter operators: literal wildcards and true case-insensitive equality
$eqi / $nei now do real case-insensitive equality (= LOWER(?)), not LIKE, so values with %, _, or a trailing \ no longer act as wildcards or crash some databases. Substring operators ($contains, $startsWith, $endsWith, and case-insensitive variants) now treat %, _, and \ in the filter value as literal characters. If you relied on % / _ inside those filters as SQL wildcards, update filters to match the new literal semantics.
(#26476)
❤️ Thank You
- Adrien L @Adzouz
- Adrien Lepoutre @Adzouz
- Andrei L @unrevised6419
- Arthur Moreau
- Ayoub Hidri @ayhid
- Bassel Kanso
- Ben Irvin
- DMehaffy
- Dominik Juriga @dominik-juriga
- Giulio Montagner @giu1io
- Jamie Howard @jhoward1994
- magics @hugomagics
- Mason McElvain @masonmcelvain
- Nico André
- Syed Osama Ali Shah @Osamaali313
- Vansh Parmar @vansh1011
- Vishal Kumar Singh @singhvishalkr
v5.51.1
5.51.1 (2026-07-29)
🔥 Bug fix
- respect field length constraints in AI localizations and isolate… (#26880)
- wording and merging sort options (844c8d625d)
- preserve sorting on view change (6ed616ab9a)
- admin: scope audit logs user filter to log authors (#27047)
- content-manager: homepage recent-documents dates serialize as empty objects (#27066)
- core: enforce required media and relations via api.documents.strictRelations (#27028)
- database: return [] for empty morphMany on read (#27090)
- strapi: prevent duplicate public assets in Vite builds (#27089)
⚙️ Chore
- admin: allow RFC 6265 control-char regex under develop eslint rules (e8338bb6ba)
- ci: remove admin bundle-size workflow (#27070)
- deps: bump brace-expansion from 1.1.14 to 1.1.16 (#27071)
- deps: bump shell-quote from 1.8.4 to 1.10.0 (#27072)
- deps: bump body-parser from 1.20.4 to 1.20.6 (#27094)
- deps: bump dompurify from 3.4.11 to 3.4.12 (#27095)
- deps: bump fast-uri from 3.1.2 to 3.1.4 (#27098)
- deps: bump use-context-selector from 1.4.1 to 1.4.4 (#27061)
- deps: bump cropperjs from 1.6.1 to 1.6.2 (#27060)
- deps: upgrade handlebars, axios, tar, and related transitive deps (#27091)
- deps: bump @radix-ui/react-toolbar from 1.0.4 to 1.1.11 (#27059)
- email-nodemailer: migrate unit tests from jest to vitest (#27074)
- email-sendmail: migrate unit tests from jest to vitest (#27075)
- upload-local: migrate unit tests from jest to vitest (#27073)
⚠️ Changes to be aware of
Required media and relations: opt-in strictRelations
New config api.documents.strictRelations enforces required media and relations on publish (drafts can still be empty). On by default for new projects; existing apps are unchanged until you set it. To opt in, set documents.strictRelations: true in config/api.
(#27028)
Empty multiple media / morphMany now returns []
Populated empty morphMany relations (including type: 'media', multiple: true) serialize as [] instead of null, matching other to-many relations. This is unconditional and not gated by strictRelations. If clients, webhooks, or integrations check field === null for empty galleries / morphMany, treat [] as empty instead (e.g. !field?.length).
(#27090)
❤️ Thank You
- Adrien L @Adzouz
- Adrien Lepoutre @Adzouz
- akash-dabhi-qed @akash-dabhi-qed
- Ben Irvin
- Giulio Montagner @giu1io
- Gonzalo Andres Garcia @gonbaum
- Mehdi Rezaei @mehdiraized
- Nico André
v5.51.0
5.51.0 (2026-07-23)
🚀 New feature
- data-transfer: add exclude/only content type CLI filters (#26915)
- i18n: add locale codes for Abkhazian and Circassian (Adyghe and Kabardian) (#26255)
🔥 Bug fix
- preserve order when reordering a relation to the start of a list (#26112)
- singleton modules for consistent runtime instances (#27064)
- admin: admin session token respects configured admin-cookie-path (#25478, #26300)
- admin: make plugin/setting "Select all" work in admin token permissions (#27027)
- admin: revalidate SPA shell to avoid stale chunk imports (#27039)
- admin: expire admin reset-password tokens (#27020)
- admin: improve SSO session metadata and logout revocation (#26872)
- admin: blank admin in develop from prism language prebundle (#27086)
- admin: SSO remote logout infinite redirect (cookie path) (#27100)
- content-manager: pre-bundle prism language plugins for all apps (#26978)
- content-manager: respect disconnected draft relations in publish warning (#26871)
- content-manager: validate items passed to plugin action APIs (#27008)
- content-manager: skip blocks editor remount on equal value echoes (#27042)
- content-manager: keep preview button mounted during document churn (#27043)
- content-releases: normalise release id so rescheduling cancels the stale job (#27063
- core: enforce default maxLength 255 for string fields (#26128)
- core: preserve draft relation order in discard-drafts migration (#26851)
- core: propagate server updatedAt in addFirstPublishedAtToDraft to avoid false modified flag (#26525)
- create-strapi-app: npm ci fails on fresh npm scaffold (#27038)
- create-strapi-app: missing @strapi/database dependency breaks pnpm builds (#27083)
- database: apply MySQL dialect configure to resolved connection functions (#26646)
- graphql: include private fields in mutation inputs (#26489)
- types: update LoadedPlugin type to understand factories (#25298)
- upload: report real upload progress in the media library (#27045)
- users-permissions: use correct i18n ids for role notifications (#27044)
- users-permissions: fix role notification translations (#26933)
⚙️ Chore
- merge main into develop after 5.50.2 release (9d93244f7e)
- deps: bump ws from 8.21.0 to 8.21.1 (#27030)
- deps: bump tar from 7.5.18 to 7.5.20 (#27029)
- deps: bump linkify-it from 5.0.0 to 5.0.2 (#26886)
- email-mailgun: migrate unit tests from jest to vitest (#27069)
- types: per-client database connection types (#26949)
- users-permissions: replace grant/purest/jwk-to-pem with fetch and crypto (#26820)
- utils: upgrade preferred-pm to v5 with dynamic import (#26822)
❤️ Thank You
- Akash Santra @Akash504-ai
- akash-dabhi-qed @akash-dabhi-qed
- Akash! @Akash5908
- Andrei L @unrevised6419
- Andrew Bone
- Ben Irvin
- deferral-opium
- Dijedon @dijedontahiri
- Giulio Montagner @giu1io
- Jamie Howard @jhoward1994
- jasleenkaur-qed42 @jasleenkaur-qed42
- KaiNative
- Maher @abaza738
- Mohammad Arshid @Mohammadarshid
- Rowan-Paul
- Sami Waseem @AbdulSamiWaseem
- santichausis @santichausis
v5.50.2
5.50.2 (2026-07-15)
🚀 New feature
- admin: make admin auth cookie name configurable (#26931)
- i18n: complete Korean (ko) translation (#26941)
🔥 Bug fix
- admin: prevent deprecated CJS Vite Node API warning on startup (#26947)
- admin: pre-commit fails when staging files ignored by ESLint (#26958)
- admin: show plan label instead of edition in dashboard (#26891)
- admin: restore runtime default for context helper (#26809)
- ci: reduce false positives in issue template checker (#26955)
- ci: use npm install in issue template checker workflow (#26974)
- content-manager: clear stale Blocks editor selection on external value change (#26959)
- core: backward compat - reject 'status' attribute when draftAndPublish is enabled (#26890)
- core: validate license registry responses with zod (#26935)
- core: preserve duplicate form relation edits when cloning (#26961)
- data-transfer: bump ws to 8.21.0 to fix CVE-2026-48779 (#26898)
- database: include status sort expression in SELECT when using DISTINCT (#26751)
- database: lint script does not run type check (#26819)
- email: only warn about sendmail provider in development (#26893)
- openapi: add bearerAuth and bracket pagination query params (#26948)
- strapi: auto-exclude pre-built plugin UI libs from Vite optimizeDeps (#26944)
- strapi: fix develop blank admin from optimizeDeps auto-exclude (#27014)
- upgrade: prompt to pin ranged @strapi/* dependencies before upgrading (#26929)
- upload: load remote asset thumbnails with crossOrigin to prevent CORS preview failures (#26581, #26901)
- utils: align remaining convert-query-params errors with ValidationError (#26908)
⚙️ Chore
- ai-tooling: sync skills when cursor sets up a new worktree (#26954)
- data-transfer: clarify --exclude files CLI messaging (#26914)
- deps: patch/minor dependency bumps (#26823)
- deps: bump @xhmikosr/decompress from 10.2.0 to 10.2.1 (#26928)
- deps: bump sharp from 0.33.5 to 0.34.5 (#26993)
- deps: bump @internationalized/date from 3.5.4 to 3.12.1 (#26994)
- deps: bump design-system and icons to v2.2.3 (#27002)
- eslint: enforce zero warnings in package lint scripts (#26922)
- husky: run git hooks through yarn exec (#27006)
- tooling: remove unused find-up after lint-staged 16 (#26792)
- types: drop CommonJS tsconfig overrides, build JS via rollup (#26934)
- typescript: scope tsconfig types per workspace (#26699)
- typescript-utils: migrate to typescript (#26811)
- typescript-utils: bump internal deps to 5.50.1 (#26946)
⚠️ Changes to be aware of
Admin auth cookie name
You can set admin.auth.cookie.name in admin config to rename the access-token cookie (default remains jwtToken). Useful when another app on a shared parent domain sets a jwtToken cookie and breaks admin login.
(#26931)
status attribute with Draft & Publish
In v5, status is reserved for draft/published filtering. If a content type has Draft & Publish enabled and a custom status field, Strapi now logs a startup warning instead of failing boot. The Content-Type Builder still blocks adding status or enabling D&P when status already exists.
(#26890)
Upgrade tool and ranged @strapi/* versions
@strapi/upgrade now warns and offers to pin ranged @strapi/* dependencies (e.g. ^5.50.0) before upgrading, so upgrades don't silently report "already up-to-date" when node_modules resolved ahead of package.json.
(#26929)
❤️ Thank You
- Abdallah M. @abdallahmz
- akash-dabhi-qed @akash-dabhi-qed
- Ali Ataf @aliataf
- Andrei L @unrevised6419
- arun @aun009
- Bassel Kanso
- Ben Irvin
- Giulio Montagner @giu1io
- Jamie Howard @jhoward1994
- jasleenkaur-qed42
- moduvoice
- Monu Meena @Monu01123
- Nico André
v5.50.1
5.50.1 (2026-07-08)
🚀 New feature
🔥 Bug fix
- give the ability to open a list item in a new tab (#26853)
- admin: translate enumeration option labels in the content manager (#26837)
- admin: seat limit billing links (#26728)
- cloud: hide deploy menu in production using currentEnvironment (#26733)
- content-manager: allow reading hidden content types for relation targets (#26844)
- content-manager: preserve i18n locale on navigation and guard component schema race condition (#26167)
- core: preserve self-referential relation order on child publish (#26838)
- core: preserve published self-referential relation state (#26932)
- database: prevent crash when reordering and removing a relation in the same save (#26210)
- documentation: allow array populate parameter (#26358)
- examples: enable strict TypeScript in dev sandboxes (#26780)
- generators: detect plugin language from output path (#26750)
- review-workflows: add server eslint config and declare server deps (#26800)
- strapi: resolve admin Vite aliases from @strapi/admin closure (#26756)
- typescript-utils: emit namespace keyword instead of deprecated module (#26195)
- upload: accept single-file arrays on replacement (#26405)
- utils: align polymorphic populate validation with conversion (#26848)
- utils: return 400 instead of 500 for invalid sort order/params (#26907)
📚 Documentation Changes
- Highlight destructive operation in transfer engine (#25081)
⚙️ Chore
- fix lint warnings (#26818)
- deps: bump nodemailer from 8.0.9 to 9.0.1 (#26721)
- deps: bump qs from 6.15.2 to 6.15.3 (#26846)
- deps: bump tar from 7.5.16 to 7.5.17 (#26847)
- deps: bump js-yaml from 3.14.2 to 3.15.0 (#26888)
- deps: bump tar from 7.5.17 to 7.5.18 (#26887)
- deps-dev: bump eslint-plugin-prettier in the eslint group (#26828)
- deps-dev: bump @rollup/plugin-swc in the rollup group (#26906)
- deps-dev: align @babel/* family to 7.29.7 (#26911)
💅 Enhancement
- ci: block community PRs targeting main (#26854)
- content-manager: keep sidebar primary actions and search bar fixed… (#26867)
❤️ Thank You
- Adrien L @Adzouz
- Alexandre Noblet @AlexNbl27
- Andrei L @unrevised6419
- Aryan Katiyar @Kelpy2004
- Bassel Kanso
- Ben Irvin
- jasleenkaur-qed42
- Maksim Zhukau @MaksZhukov
- Mateusz Lesiak
- mathildeleg @mathildeleg
- mehmet turac @mturac
- Nico André
- santichausis @santichausis
- Shivam S @BIGSUS24
- Steven @compair-steven
- Zyggzz @Zyggzzz
v5.50.0
5.50.0 (2026-07-02)
🚀 New feature
- admin: add active devices session management (#26628)
- cli: add security defaults to create-strapi-app templates (#26737)
- database: export lifecycle event type (#25637)
- provider-email-sendgrid: add region option for EU data residency (#25907)
- provider-upload-aws-s3: accept a credential provider function (#26796)
- translations: comprehensive Japanese (ja) translation update for admin and 9 plugins (#26687)
- ts: augment all context error response methods (#25424)
🔥 Bug fix
- refresh token cookies missing Max-Age when sessions.cookie.maxAg… (#26747)
- add test database healthchecks (#26511)
- generate apis in named directories (#26354)
- admin: retry lazy chunk loads and improve loading and error UX (#25954)
- admin: open "Upgrade your admin panel" link in new tab (#26510)
- admin: remove @ts-expect-error in useQueryParams hook (#25006)
- admin: hide boolean clear action when field is disabled (#26294)
- admin: restore default locale in permissions when adding i18n to ct (#26548)
- admin: keep static fallback paths url-safe (#26518)
- admin: stop storing IP addresses in session metadata (#26873)
- ci: use allowlisted thollander action ref in experimental publish workflow (#26768)
- content-api: validate populate for polymorphic structures (#25854)
- content-manager: warn before publishing with draft relations (#26736)
- content-manager: use ListViewTable relation-loaded translation key (#26798)
- content-manager: serve live preview script from server endpoint (#26732)
- content-manager: capitalize component category names in dynamic zone (#24426, #26337)
- content-manager: add Japanese EditView shortcut hint translations (#26814)
- content-manager: prevent dynamic zone crash when value is null (#26816)
- content-manager: skip publish warning for M2M links to published entries (#26858)
- content-type-builder: improve component category validation error message (#25455)
- core: preserve M2M relation order on published version after reo… (#26791)
- core: maxFileSize error not detected in body middleware (#25011)
- core: resolve relations on non-localized entries with stale locale column (#26805)
- create-strapi-app: scaffold pnpm 11 allowBuilds for Strapi Cloud (#26757)
- create-strapi-app: enable strict TypeScript in app scaffolds (#26779)
- create-strapi-app: limit odd Node major warning to versions before 26 (#26810)
- data-transfer: restore localizations links that use document_id refs (#26870)
- graphql: preserve M2M relation order with pagination (#26577, #26785)
- test: tighten jest ignore patterns to match path segments (#26753)
- translations: correct ja "characters" mistranslation in WYSIWYG controls (#26845)
- types: tighten Core.Config typings with backward-compatible deprecations (#26787)
- upload: disable asset editing and deletion on published entries (#26127)
- users-permissions: accept documentId for the role relation on user create/update (#26715)
- users-permissions: correct "occured" → "occurred" typo in error notifications (#26508)
- utils: prevent crash on null dynamic zone entry during traversal (#24303, #26842)
📚 Documentation Changes
- fix typos and grammar slips in content-manager docs (#26600)
⚙️ Chore
- add ai-tooling sync script for skill symlinks (#26594)
- rename ai-tooling yarn scripts to ai:* (#26767)
- reduce Vercel noise on PRs (contributor-docs ignore step) (#26772)
- cloud plugin updates (#26801)
- update cli deploy copies (f0fa460525)
- deps: hoist @types/node to root and align with 20, min supported engine (#26291)
- deps: upgrade TypeScript to 5.9.3 (#26782)
- deps: bump hono from 4.12.23 to 4.12.27 (#26761)
- deps: bump design-system to v2.2.1 (#26788)
- deps: bump axios from 1.18.0 to 1.18.1 (#26762)
- deps: upgrade lint-staged to 16 and scope linting to staged files (#26765)
- deps: remove unused @strapi/ts-zen dev dependency (#26759)
- typescript: enable erasableSyntaxOnly and noUncheckedSideEffectImports (#26790)
- workflows: make documentation flag name more obvious (#26649)
💅 Enhancement
- admin: add uz-Cyrl native name to languageNativeNames (#24920)
- strapi: lazy-load TypeScript chain for non-build CLI commands (#26265)
- utils: add env.required for strict scaffold secrets (#26830)
🚨 Security
- users-permissions: default legacy JWT verify to HS256 (#26752)
❤️ Thank You
- Akash Santra @Akash504-ai
- Andrei L @unrevised6419
- Arthur
- Aurélien GEORGET
- Ayoub Hidri @ayhid
- Ben Irvin
- Daiske @daiske
- Florent Baldino @Baldinof
- greymoth
- ivseb @ivseb
- jasleenkaur-qed42
- Jian Zhang @Jian-Zhang08
- Joseph Ajayi @ajayi-joseph
- kdt523
- kibwashere
- Maksim Zhukau @MaksZhukov
- mariekirsch @mariekirsch
- mathildeleg @mathildeleg
- mehmet turac @mturac
- mhsnsfh
- Minh Lê @DucMinhNe
- Nico André
- Niels Kaspers @nielskaspers
- Nuraliev Alirahmon
- Pierre Wizla
- Rowan-Paul
- Tewson Seeoun @tewson
- Vibhu Gupta @VibhuGupta-dev
- Vishal Kumar Singh @singhvishalkr
v5.49.0
5.49.0 (2026-06-24)
🚀 New feature
- mcp: export defineTool/defineResource/definePrompt builders (#26603)
🔥 Bug fix
- add support for initiallySelectedAssets (#26679)
- homepage dashboard duplicates entries for users with multiple roles (#25860)
- avoid buffering large uploads for MIME detection (#26678)
- throw ValidationError when populate exceeds qs arrayLimit (#25632, #25916)
- push anchor into view to prevent off-screen tooltips (#26303)
- admin: support array of links in StrapiApp.addSettingsLink (#26433)
- admin: admin users logged out mid-session by access-token expiry timer (#26680)
- content-manager: use top-level Core type import in MCP types (#26681)
- content-manager: save draft with Cmd/Ctrl+Enter, publish with Cmd/Ctrl+Shift+Enter (#26621)
- content-manager: reduce MCP relation output to identity-only shape (#26560)
- content-manager: deduplicate MCP tool names when plugin has multiple content types (#26710)
- core/core: mcp misleading lifecycle docs (#26698)
- create-strapi-app: allow pnpm to build better-sqlite3 for SQLite scaffolds (#26675)
- data-transfer: transfer admin menu and auth logos with configuration (#26425)
- database: stop full-schema component_type IN on dynamic zone populate (#26734)
- document-service: preserve published relations from non-dp sources (#26654)
- strapi: default allowedHosts and pin Vite HMR to main server in dev (#26244)
- types: add explicit return types to recursive functions (#26704)
📚 Documentation Changes
- fix spelling typos in content-manager relations guide (#26724)
⚙️ Chore
- removing coderabbit status (#26703)
- core: upgrade package-json to 10.0.1 + rollup interop 'auto' (#26673)
- deps: bump markdown-it from 14.1.1 to 14.2.0 in the richtext-editor-security group across 1 directory (#26688)
- deps: bump dompurify from 3.4.5 to 3.4.9 (#26684)
- deps: bump nodemailer from 8.0.5 to 8.0.9 (#26689)
- deps: bump tar from 7.5.11 to 7.5.16 (#26691)
- deps: bump form-data from 4.0.4 to 4.0.6 (#26692)
- deps: bump anthropics/claude-code-action from 1.0.123 to 1.0.132 (#26727)
- deps: bump piscina from 4.9.2 to 4.9.3 (#26716)
- deps: bump undici from 6.25.0 to 6.27.0 (#26714)
- deps: bump dompurify from 3.4.9 to 3.4.11 (#26719)
- deps-dev: bump @babel/core (#26667)
💅 Enhancement
- upload: add optional replace method to upload providers (#26582)
❤️ Thank You
- akash-dabhi-qed @akash-dabhi-qed
- Andrei L @unrevised6419
- Andrew Bone
- Bassel Kanso @Bassel17
- Ben Irvin
- Giulio Montagner @giu1io
- guoyangzhen
- jasleenkaur-qed42
- Nico André
- Shivam S @BIGSUS24
- Simon Norris @cache-your-dreams
- Travis Swientek @travelton
- Vallabh Mahajan @Vallabh-1504
- Vishal Kumar Singh @singhvishalkr
⚠️ Changes to be aware of
Content Manager keyboard shortcuts
Save a draft with Cmd/Ctrl+Enter (or Cmd/Ctrl+S). Publish with Cmd/Ctrl+Shift+Enter. Since v5.31.3, plain Cmd/Ctrl+Enter published immediately — that shortcut now saves instead. (#26621)
v5.48.1
5.48.1 (2026-06-17)
🚀 New feature
- linking to the Billing Portal (3df113f545)
- pointing Upsell Banner to Strapi Billing (06b0c31f47)
- add optional openapi spec route (#26239)
- updating billing portal address (2d3fea21ff)
- openapi: gate endpoint access with config (#26574)
- upload: add paginated GET /api/upload/files/page endpoint (#26597)
🔥 Bug fix
- upload returns unsigned URL on update media info (#25195)
- widgets show error when role has no access to mainfield of ct (#26537)
- correct IME Enter key handling in BlocksInput (#24997)
- admin: return empty object for empty json body in fetch client (#26277)
- admin: exclude disabled plugins from admin build (#26448)
- admin: rate limit and serialize first admin registration (#26576)
- admin: validate current user email updates (#26591)
- admin: guard stale admin configuration (#26625)
- build: build does not run install; add install-deps arg (#26483)
- ci: run build:size as full command for compressed-size-action v3 (#26556)
- ci: restore allowed paths-filter pin (#26575)
- ci: avoid syncing CPR labels to CMS tickets (#26648)
- content-manager: use ReadonlyArray for layout prop and fix Repeatable test fixture (#26522)
- content-manager: raise z-index of code block language selector (#25010, #26324)
- content-manager: dedupe bulk delete document ids (#26613)
- content-manager: replace sanitize-html with dompurify in Wysiwyg preview (#26150)
- core: validate numeric inputs before DB unique checks (#26101)
- core/admin | content-manager: combine multi-role field-level permissions (#26055)
- data-transfer: skip links referencing data that was never transferred (#26531)
- data-transfer: buffer push assets before invoking uploadStream (#26086)
- database: restore join-table relation sort order in components (#26553)
- database: avoid double finalising completed transactions (#26122)
- database: move document_id secondary indexes to schema sync (#26241)
- strapi: stabilize admin redux deps during upgrade (#26249)
- tsconfig: remove lodash from server compilerOptions.types (#26627)
- upload: folder navigation bugs in Media Library (#26515)
- upload: preserve animation frames in GIF and WebP images (#26126)
- users-permissions: support documentId user relations (#26607)
- utils: ignore empty sort when building orderBy (#26427)
📚 Documentation Changes
- add CLAUDE.md alias and link PR template from AGENTS.md (#26251)
- fix typos across contributor docs (#26590)
- fix broken relative cross-doc links (#26601)
- deprecate Node 20 in documentation (#26623)
- openapi: add contributor documentation (#26410)
⚙️ Chore
- remove experimental-dev example app (#26552)
- update .gitignore for AI tooling directories (#26526)
- release v5.48.0 update develop (#26599)
- adding check for valid template on issue creation (#26546)
- adding translations for manage subscription (aa0b3da3eb)
- getting tests to pass (d2c06c6ca2)
- *: support Node 26 (#26232)
- ai/skills: add writing-a-skill skill (#26428)
- ai/skills: add commit conventions (#26431)
- ci: drop Node 20 from test workflow matrices (6f1a21c528)
- ci: drop Node 20 from test workflow matrices (#26609)
- core/strapi: dynamically import browserslist-to-esbuild (#25507)
- data-transfer: move types into src so they are type-checked (#26352)
- deps: bump axios from 1.16.1 to 1.17.0 (#26539)
- deps: bump the testing-library group across 1 directory with 2 updates (#26506)
- deps: bump actions/setup-node from 4 to 6 (#26496)
- deps: bump actions/stale from 10 to 10.2.0 (#26497)
- deps: bump preactjs/compressed-size-action from 2 to 3 (#26498)
- deps: resolve vulnerable transitive deps via lockfile dedupe and resolutions (#26540)
- deps: bump cheerio from 1.0.0 to 1.2.0 (#26569)
- deps: bump dorny/paths-filter from 3.0.3 to 4.0.1 (#26566)
- deps: bump actions/download-artifact from 4.3.0 to 8.0.1 (#26564)
- deps: bump follow-redirects from 1.15.6 to 1.16.0 (#26580)
- deps: bump shell-quote from 1.8.1 to 1.8.4 (#26585)
- deps: bump @vitejs/plugin-react-swc (#26567)
- deps: bump the rollup group across 1 directory with 3 updates (#26505)
- deps: bump nrwl/nx-set-shas from 4 to 5 (#26565)
- deps: bump anthropics/claude-code-action from 1 to 1.0.123 (#26640)
- deps: bump trunk-io/analytics-uploader from 1.15.0 to 2.0.9 (#26638)
- deps: bump rollup from 4.60.1 to 4.60.4 in the rollup group across 1 directory (#26641)
- deps: bump open from 8.4.0 to 8.4.2 (#26643)
- deps: bump stream-json and @types/stream-json (#26645)
- deps: bump koa-helmet from 7.0.2 to 7.1.0 (#26642)
- deps: bump axios from 1.17.0 to 1.18.0 (#26647)
- deps-dev: bump the eslint group across 1 directory with 10 updates (#26500)
- deps-dev: bump @types/delegates from 1.0.0 to 1.0.3 (#26570)
- deps-dev: bump the nx group across 1 directory with 2 updates (#26502)
- deps-dev: bump @types/webpack-hot-middleware from 2.25.9 to 2.25.12 (#26568)
- deps-dev: bump @types/invariant from 2.2.36 to 2.2.37 (#26644)
- repo: skip change freeze ownership check when freeze disabled (#26474)
💅 Enhancement
- admin: hide deploy-now widget in production (#26660)
- core/core: rounded thin borders for startup banner (#26273)
- graphql: use discriminated unions instead of unsafe type casting (#25913)
- upgrade: unhide and document upgrade to command (#26446)
🚨 Security
- deps: patch uuid (GHSA-w5hq-g745-h8pq) and qs DoS advisories (9aef801f35)
- deps: scope uuid/qs resolutions to affected descriptors (38b6831652)
❤️ Thank You
- Adrien L @Adzouz
- Andrei L @unrevised6419
- Andrei Varapayeu @thisavoropaev
- Arav...
v5.48.0
5.48.0 (2026-06-10)
🚀 New feature
🔥 Bug fix
- upload returns unsigned URL on update media info (#25195)
- widgets show error when role has no access to mainfield of ct (#26537)
- admin: return empty object for empty json body in fetch client (#26277)
- build: build does not run install; add install-deps arg (#26483)
- ci: run build:size as full command for compressed-size-action v3 (#26556)
- ci: restore allowed paths-filter pin (#26575)
- content-manager: use ReadonlyArray for layout prop and fix Repeatable test fixture (#26522)
- content-manager: raise z-index of code block language selector (#25010, #26324)
- core: validate numeric inputs before DB unique checks (#26101)
- database: restore join-table relation sort order in components (#26553)
- database: avoid double finalising completed transactions (#26122)
- upload: folder navigation bugs in Media Library (#26515)
- upload: preserve animation frames in GIF and WebP images (#26126)
- utils: ignore empty sort when building orderBy (#26427)
📚 Documentation Changes
- openapi: add contributor documentation (#26410)
⚙️ Chore
- remove experimental-dev example app (#26552)
- update .gitignore for AI tooling directories (#26526)
- deps: bump axios from 1.16.1 to 1.17.0 (#26539)
- deps: bump the testing-library group across 1 directory with 2 updates (#26506)
- deps: bump actions/setup-node from 4 to 6 (#26496)
- deps: bump actions/stale from 10 to 10.2.0 (#26497)
- deps: bump preactjs/compressed-size-action from 2 to 3 (#26498)
- deps: resolve vulnerable transitive deps via lockfile dedupe and resolutions (#26540)
- deps: bump cheerio from 1.0.0 to 1.2.0 (#26569)
- deps: bump dorny/paths-filter from 3.0.3 to 4.0.1 (#26566)
- deps: bump actions/download-artifact from 4.3.0 to 8.0.1 (#26564)
- deps-dev: bump the eslint group across 1 directory with 10 updates (#26500)
- deps-dev: bump @types/delegates from 1.0.0 to 1.0.3 (#26570)
- deps-dev: bump the nx group across 1 directory with 2 updates (#26502)
- repo: skip change freeze ownership check when freeze disabled (#26474)
💅 Enhancement
- core/core: rounded thin borders for startup banner (#26273)
- graphql: use discriminated unions instead of unsafe type casting (#25913)
- upgrade: unhide and document upgrade to command (#26446)
🚨 Security
- deps: patch uuid (GHSA-w5hq-g745-h8pq) and qs DoS advisories (9aef801f35)
- deps: scope uuid/qs resolutions to affected descriptors (38b6831652)
❤️ Thank You
- Andrei L @unrevised6419
- Andrei Varapayeu @thisavoropaev
- Arav Menon @Arav-Menon
- Aurélien GEORGET
- Ben Irvin
- Dante Calderon @dantehemerson
- Jamie Howard @jhoward1994
- Maksim Zhukau @MaksZhukov
- mathildeleg @mathildeleg
- Nico André
v4.26.2
⚠️ Note: This is the final Strapi 4 release ⚠️
No further updates to Strapi 4 will be published, this release serves as the final version of Strapi 4 which is considered EOL (End-Of-Life) as of April 30th, 2026. All Strapi users should migrate to Strapi 5: https://docs.strapi.io/cms/migration/v4-to-v5/introduction-and-faq
Also please note, this does include Strapi Customers as well. Strapi Cloud will still continue to function with Strapi 4 but that may be subject change in the near future without warning.
What's Changed
Security
- Fixed a critical vulnerability where relational filtering could expose sensitive data through insufficient query sanitization. See GHSA-rjg2-95x7-8qmx / CVE-2026-27886.
- Upgraded
tarto v7 to address security warnings. - Applied v4 dependency security and maintenance updates.
Fixes
- Enforced unique admin email validation when updating the authenticated user profile.
Compatibility
- Added Node.js 22 support for Strapi v4.
Full Changelog: v4.26.1...v4.26.2