GHSA-238x-w2j9-gwwr: Npm/payload vulnerability

Published Oct 6, 2026
·
Updated

Impact

Users with read access to other user documents could access their active API keys. An exposed key grants the target account’s permissions until rotated or disabled.

You are affected if:

- An authentication collection enables useAPIKey. - Users have read access to other user documents containing active API keys.

Patches

Users should upgrade payload packages to >= 3.90.0 or >= 4.0.0-canary.34.

Workarounds

Disable useAPIKey or restrict users to reading only their own authentication document. Rotate any API key that may have been exposed.

Affected Software

2 affected componentsFixes available
npm/payload>=4.0.0-canary.0<4.0.0-canary.34
4.0.0-canary.34
npm/payload>=3.0.0<3.90.0
3.90.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/payload to a version that resolves this vulnerability.

    Fixed in 4.0.0-canary.34
  2. Upgrade

    Upgrade npm/payload to a version that resolves this vulnerability.

    Fixed in 3.90.0
  3. Upgrade

    Upgrade Payload packages to a version that resolves this vulnerability.

    Fixed in 3.90.0
  4. Upgrade

    Upgrade Payload packages to a version that resolves this vulnerability.

    Fixed in 4.0.0-canary.34
  5. Configuration

    Disable useAPIKey or restrict users to reading only their own authentication document.

    Authentication collection useAPIKey and authentication document read access = Disable useAPIKey, or restrict users to reading only their own authentication document
  6. Operational

    Rotate any API key that may have been exposed.

Event History

Oct 6, 2026
Advisory Published
via GitHub·04:18 PM
Data Sourced
via GitHub·04:18 PM
DescriptionWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are affected?

Affected deployments have an authentication collection with useAPIKey enabled and allow users to read other users' documents that contain active API keys. Both conditions are required.

2

What access does an attacker need to exploit this?

The attacker needs read access to another user's authentication document containing an active API key. A retrieved key provides the permissions of the account that owns it until it is rotated or disabled.

3

What can be done if an upgrade cannot be applied immediately?

Disable useAPIKey, or restrict users so they can read only their own authentication document. Rotate any API keys that may already have been exposed.

4

How can we determine whether API keys may have been exposed?

Review whether users could read other users' authentication documents while useAPIKey was enabled, and identify documents with active API keys. Any keys in documents accessible to other users should be treated as potentially exposed and rotated.

5

Which package versions contain the fix?

Upgrade Payload packages to version 3.90.0 or later, or to 4.0.0-canary.34 or later.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203