v4.26.2

huggingface/finetrainersv4.26.2Jun 9, 2026by Bassel17

AI Summary

This is the final Strapi 4 release, marking it as End-Of-Life. It includes a critical security fix for relational filtering data exposure, Node.js 22 support, and dependency updates.

Key Highlights

  • Marked as the final Strapi 4 release (EOL as of April 30, 2026).
  • Fixed critical vulnerability exposing sensitive data via relational filtering.
  • Added Node.js 22 support for Strapi v4.
  • Upgraded tar to v7 to address security warnings.

New Features

  • Node.js 22 support.

Full Release Notes

## :warning: Note: This is the final Strapi 4 release :warning: 

No further updates to Strapi 4 will be published, this release serves as the final version of Strapi 4 which is considered EOL (End-Of-Life) as of April 30th, 2026. All Strapi users should migrate to Strapi 5: https://docs.strapi.io/cms/migration/v4-to-v5/introduction-and-faq

Also please note, this does include Strapi Customers as well. Strapi Cloud will still continue to function with Strapi 4 but that may be subject change in the near future without warning.

## What's Changed

### Security
* Fixed a critical vulnerability where relational filtering could expose sensitive data through insufficient query sanitization. See [GHSA-rjg2-95x7-8qmx](https://github.com/strapi/strapi/security/advisories/GHSA-rjg2-95x7-8qmx) / CVE-2026-27886.
* Upgraded `tar` to v7 to address security warnings.
* Applied v4 dependency security and maintenance updates.

### Fixes
* Enforced unique admin email validation when updating the authenticated user profile.

### Compatibility
* Added Node.js 22 support for Strapi v4.

**Full Changelog**: https://github.com/strapi/strapi/compare/v4.26.1...v4.26.2