GHSA-p223-2wr2-j562: Path Traversal
Impact Under certain conditions, an authenticated user with permission to modify uploads could cause unintended files to be removed during file cleanup. This may result in data loss or service disruption.
You are affected if: - You use Payload upload collections with local file storage. - Untrusted authenticated users can update or delete uploads.
Deployments that restrict upload management to trusted users are less exposed.
Patches Payload now validates uploaded filenames and ensures file cleanup remains within the configured upload directory.
Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Workarounds Restrict upload update and deletion operations to trusted users and validate submitted filenames. These measures are temporary mitigations. Upgrading to a patched version is recommended.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/payloadto a version that resolves this vulnerability.Fixed in 4.0.0-canary.34 - Upgrade
Upgrade
npm/payloadto a version that resolves this vulnerability.Fixed in 3.90.0 - Upgrade
Upgrade
Payload packagesto a version that resolves this vulnerability.Fixed in 3.90.0 - Upgrade
Upgrade
Payload packagesto a version that resolves this vulnerability.Fixed in 4.0.0-canary.34 - Compensating control
Restrict upload update and deletion operations to trusted users.
- Compensating control
Validate submitted upload filenames and ensure file cleanup remains within the configured upload directory.
Event History
Frequently Asked Questions
Which deployments are most exposed?
Deployments using Payload upload collections with local file storage are affected when untrusted authenticated users can update or delete uploads. Restricting upload management to trusted users reduces exposure.
What access does an attacker need?
An attacker must be authenticated and have permission to modify uploads. Exploitation is associated with upload update or deletion operations under certain conditions.
What can be done before upgrading?
Restrict upload update and deletion operations to trusted users and validate submitted filenames. These are temporary mitigations; upgrading is recommended.
Which versions contain the fix?
Upgrade Payload packages to version 3.90.0 or later, or to 4.0.0-canary.34 or later.