GHSA-qf28-8hc6-vwrp: Npm/@payloadcms/plugin-import-export vulnerability
Impact An unauthenticated user could cause unintended application behavior when the Import Export plugin is enabled, allowing an attacker to submit and execute remote code (RCE).
Applications that do not use @payloadcms/plugin-import-export are not affected.
Patches Users should upgrade Payload packages to >= 3.88.0 or >= 4.0.0-canary.27.
Workarounds Upgrading is recommended. Until then, disable the Import Export plugin or restrict access to its endpoints.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@payloadcms/plugin-import-exportto a version that resolves this vulnerability.Fixed in 4.0.0-canary.27 - Upgrade
Upgrade
npm/@payloadcms/plugin-import-exportto a version that resolves this vulnerability.Fixed in 3.88.0 - Upgrade
Upgrade
Payload packagesto a version that resolves this vulnerability.Fixed in 3.88.0 - Upgrade
Upgrade
Payload packagesto a version that resolves this vulnerability.Fixed in 4.0.0-canary.27 - Configuration
Disable the Import Export plugin until upgrading.
@payloadcms/plugin-import-export enabled = false - Compensating control
Restrict access to the @payloadcms/plugin-import-export endpoints.
Event History
Frequently Asked Questions
Which applications are exposed to this issue?
Only applications using the @payloadcms/plugin-import-export Import Export plugin are affected. Applications that do not use that plugin are not affected.
Does an attacker need an account to exploit it?
No. The issue can be triggered by an unauthenticated user when the Import Export plugin is enabled.
What can be done if an upgrade cannot be applied immediately?
Disable the Import Export plugin, or restrict access to its endpoints until an upgrade is possible.
Which versions contain the fix?
Upgrade Payload packages to version 3.88.0 or later, or to 4.0.0-canary.27 or later.