v5.48.0
pascalorg/editorv5.48.0Jun 10, 2026by internal-releases[bot]
AI Summary
Introduces optional OpenAPI spec support and addresses critical bugs in uploads, database transactions, and content management, alongside security patches.
Key Highlights
- New optional OpenAPI spec route with config-based endpoint access control.
- Fixed upload returns unsigned URL on update and Media Library navigation bugs.
- Patched UUID and QS DoS vulnerabilities.
- Improved database transaction finalization and content manager layout props.
New Features
- Optional OpenAPI spec route.
- Upgrade command unhidden and documented.
Full Release Notes
## 5.48.0 (2026-06-10) ### 🚀 New feature - add optional openapi spec route ([#26239](https://github.com/strapi/strapi/pull/26239)) - **openapi:** gate endpoint access with config ([#26574](https://github.com/strapi/strapi/pull/26574)) ### 🔥 Bug fix - upload returns unsigned URL on update media info ([#25195](https://github.com/strapi/strapi/pull/25195)) - widgets show error when role has no access to mainfield of ct ([#26537](https://github.com/strapi/strapi/pull/26537)) - **admin:** return empty object for empty json body in fetch client ([#26277](https://github.com/strapi/strapi/pull/26277)) - **build:** build does not run install; add install-deps arg ([#26483](https://github.com/strapi/strapi/pull/26483)) - **ci:** run build:size as full command for compressed-size-action v3 ([#26556](https://github.com/strapi/strapi/pull/26556)) - **ci:** restore allowed paths-filter pin ([#26575](https://github.com/strapi/strapi/pull/26575)) - **content-manager:** use ReadonlyArray for layout prop and fix Repeatable test fixture ([#26522](https://github.com/strapi/strapi/pull/26522)) - **content-manager:** raise z-index of code block language selector ([#25010](https://github.com/strapi/strapi/pull/25010), [#26324](https://github.com/strapi/strapi/pull/26324)) - **core:** validate numeric inputs before DB unique checks ([#26101](https://github.com/strapi/strapi/pull/26101)) - **database:** restore join-table relation sort order in components ([#26553](https://github.com/strapi/strapi/pull/26553)) - **database:** avoid double finalising completed transactions ([#26122](https://github.com/strapi/strapi/pull/26122)) - **upload:** folder navigation bugs in Media Library ([#26515](https://github.com/strapi/strapi/pull/26515)) - **upload:** preserve animation frames in GIF and WebP images ([#26126](https://github.com/strapi/strapi/pull/26126)) - **utils:** ignore empty sort when building orderBy ([#26427](https://github.com/strapi/strapi/pull/26427)) ### 📚 Documentation Changes - **openapi:** add contributor documentation ([#26410](https://github.com/strapi/strapi/pull/26410)) ### ⚙️ Chore - remove experimental-dev example app ([#26552](https://github.com/strapi/strapi/pull/26552)) - update .gitignore for AI tooling directories ([#26526](https://github.com/strapi/strapi/pull/26526)) - **deps:** bump axios from 1.16.1 to 1.17.0 ([#26539](https://github.com/strapi/strapi/pull/26539)) - **deps:** bump the testing-library group across 1 directory with 2 updates ([#26506](https://github.com/strapi/strapi/pull/26506)) - **deps:** bump actions/setup-node from 4 to 6 ([#26496](https://github.com/strapi/strapi/pull/26496)) - **deps:** bump actions/stale from 10 to 10.2.0 ([#26497](https://github.com/strapi/strapi/pull/26497)) - **deps:** bump preactjs/compressed-size-action from 2 to 3 ([#26498](https://github.com/strapi/strapi/pull/26498)) - **deps:** resolve vulnerable transitive deps via lockfile dedupe and resolutions ([#26540](https://github.com/strapi/strapi/pull/26540)) - **deps:** bump cheerio from 1.0.0 to 1.2.0 ([#26569](https://github.com/strapi/strapi/pull/26569)) - **deps:** bump dorny/paths-filter from 3.0.3 to 4.0.1 ([#26566](https://github.com/strapi/strapi/pull/26566)) - **deps:** bump actions/download-artifact from 4.3.0 to 8.0.1 ([#26564](https://github.com/strapi/strapi/pull/26564)) - **deps-dev:** bump the eslint group across 1 directory with 10 updates ([#26500](https://github.com/strapi/strapi/pull/26500)) - **deps-dev:** bump @types/delegates from 1.0.0 to 1.0.3 ([#26570](https://github.com/strapi/strapi/pull/26570)) - **deps-dev:** bump the nx group across 1 directory with 2 updates ([#26502](https://github.com/strapi/strapi/pull/26502)) - **repo:** skip change freeze ownership check when freeze disabled ([#26474](https://github.com/strapi/strapi/pull/26474)) ### 💅 Enhancement - **core/core:** rounded thin borders for startup banner ([#26273](https://github.com/strapi/strapi/pull/26273)) - **graphql:** use discriminated unions instead of unsafe type casting ([#25913](https://github.com/strapi/strapi/pull/25913)) - **upgrade:** unhide and document upgrade to command ([#26446](https://github.com/strapi/strapi/pull/26446)) ### 🚨 Security - **deps:** patch uuid (GHSA-w5hq-g745-h8pq) and qs DoS advisories ([9aef801f35](https://github.com/strapi/strapi/commit/9aef801f35)) - **deps:** scope uuid/qs resolutions to affected descriptors ([38b6831652](https://github.com/strapi/strapi/commit/38b6831652)) ### ❤️ Thank You - Andrei L @unrevised6419 - Andrei Varapayeu @thisavoropaev - Arav Menon @Arav-Menon - Aurélien GEORGET - Ben Irvin - Dante Calderon @dantehemerson - Jamie Howard @jhoward1994 - Maksim Zhukau @MaksZhukov - mathildeleg @mathildeleg - Nico André