GHSA-v5gf-vpjc-pc7w: Npm/payload vulnerability
Impact
An unauthenticated attacker who knows an account’s email address or username could trigger Payload’s account lockout mechanism and prevent that user from signing in.
You are affected if:
Using an affected Payload version with an auth-enabled collection that uses local authentication and account lockout.
Applications that do not use Payload local authentication are not affected.
Patches
Successful password resets now clear the account’s lockout state. The forgot-password flow also enforces a configurable minimum interval between reset emails, which defaults to 15 seconds.
Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/payloadto a version that resolves this vulnerability.Fixed in 4.0.0-canary.34 - Upgrade
Upgrade
npm/payloadto a version that resolves this vulnerability.Fixed in 3.90.0 - Upgrade
Upgrade
Payload packagesto a version that resolves this vulnerability.Fixed in 3.90.0 - Upgrade
Upgrade
Payload packagesto a version that resolves this vulnerability.Fixed in 4.0.0-canary.34
Event History
Frequently Asked Questions
Which deployments are affected?
Affected deployments use an affected Payload version and have an auth-enabled collection configured for local authentication with account lockout. Applications that do not use Payload local authentication are not affected.
What does an attacker need to exploit this issue?
The attacker does not need to authenticate, but must know the target account's email address or username. They can trigger the account lockout mechanism and prevent the user from signing in.
What should be done if account lockouts have already occurred?
Upgrade Payload packages to version 3.90.0 or later, or 4.0.0-canary.34 or later. In the patched behavior, a successful password reset clears the account's lockout state.
Are password-reset emails rate limited after updating?
Yes. The forgot-password flow enforces a configurable minimum interval between reset emails, with a default interval of 15 seconds.