Impact The password-hashing configuration used a lower work factor than what is recommended.
Patches Payload now uses stronger password-hashing parameters and transparently upgrades older hashes following a successful login.
Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Workarounds Upgrading is recommended. Until you can upgrade, protect database copies and backups from unauthorized access and require strong, unique passwords.
Impact Under certain conditions, sorting readable records could reveal limited information about fields the requester was not permitted to read.
You are affected if untrusted users can query a collection, control its sorting, and sort by protected fields.
Patches Payload now applies field-level access checks to sort fields before executing queries.
Users should upgrade to >= 3.88.0 or >= 4.0.0-canary.27.
Workarounds Upgrading is recommended. Until then, prevent untrusted users from controlling sort parameters or restrict their access to affected collections.
Impact An unauthenticated user could cause unintended application behavior when the Import Export plugin is enabled, allowing an attacker to submit and execute remote code (RCE).
Applications that do not use @payloadcms/plugin-import-export are not affected.
Patches Users should upgrade Payload packages to >= 3.88.0 or >= 4.0.0-canary.27.
Workarounds Upgrading is recommended. Until then, disable the Import Export plugin or restrict access to its endpoints.
Impact
Token refresh and password reset responses could return fields that the requesting user did not have access to.
You are affected if:
- An authentication collection contains hidden or read-restricted fields.
Patches
Authentication responses now apply field access and hidden-field filtering before returning user documents. Full user documents remain available server-side for access control.
Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Custom authentication strategies remain responsible for filtering user documents returned through custom responses.
Workarounds
There is no complete workaround. Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Impact
Users with read access to other user documents could access their active API keys. An exposed key grants the target account’s permissions until rotated or disabled.
You are affected if:
- An authentication collection enables useAPIKey. - Users have read access to other user documents containing active API keys.
Patches
Users should upgrade payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Workarounds
Disable useAPIKey or restrict users to reading only their own authentication document. Rotate any API key that may have been exposed.
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an attacker can submit a request to a specific update endpoint that modifies collection documents without enforcing collection or field-level access control when orderable is enabled on a collection or join field. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Payload is a free and open source headless content management system. In versions after 3.0.0 and before 3.90.0, authenticated external URL-based upload retrieval can forward authentication data to a redirected destination that was not verified as trusted, potentially exposing a valid session to an unintended recipient. This issue is fixed in version 3.90.0.
Impact
When an auth collection defined a field-level access.update restriction on the password field, the restriction was not enforced on the server correctly.
Patches
Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Payload is a free and open source headless content management system. In versions after 3.0.0 and before 3.90.0, a custom field option that maps a field to a reserved authentication claim name can place unintended values in the authentication token issued at login. This issue is fixed in version 3.90.0.
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an unauthenticated attacker who knows an account email address or username can abuse the account lockout mechanism of a local-authentication collection to prevent that account from signing in. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.