Traceary

Catalog / Strapi

5.24.2

11 months agosecurityaddedfixedOriginal notes

:warning: Security Warning and Notice :warning:

Strapi was made aware of a vulnerably that were patched in this release, for now we are going to delay the detailed disclosure of the exact details on how to exploit it and how it was patched to give time for users to upgrade before we do public disclosure.

5.24.2 (2025-09-29)

🚀 New feature

  • Advanced Session Configuration (#24346)

🔥 Bug fix

  • database is corrupt with orphaned relations (#24316)
  • assert admin.auth.secret on bootstrap instead of init (a1b9cf7971)
  • support auth.options config in sessions (#24460)
  • stop repair script from running automatically (#24470)

❤️ Thank You

  • @jhoward1994
  • @markkaylor
  • @Bassel17
  • @innerdvations
  • Ziyi @butcherZ
  • Special thanks to @laurenskling for all the help debugging and testing!

⚠️ Notice on Admin JWT Changes

This release fundamentally changes how Admin Panel login and register JWTs work from 5.23.6.

If your project or plugins rely on undocumented functionality or internal behavior related to the Admin JWT, those implementations are very likely to break after upgrading and affect your ability to log in to the Strapi Admin Panel.

For more information on the new feature configuration settings, please see the configuration docs for Users and Permissions and Admin Panel