GHSA-66wr-7vmr-p5jqCritical
Payload authentication token field handling issue
🔗 CVE IDs covered (1)
📋 Description
Impact
Under certain field configurations, Payload could include unintended values in the authentication token issued at login.
You are affected if:
- You use an affected Payload version and have configured a custom field option that maps a field to a reserved authentication claim name.
Patches
Payload now restricts which field configuration options can influence the contents of the authentication token.
Users should upgrade payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Workarounds
There is no complete workaround. Users should upgrade payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
🎯 Affected products2
- npm/payload:>= 3.0.0, < 3.90.0
- npm/payload:>= 4.0.0-canary.0, < 4.0.0-canary.34
🔗 References (5)
- https://github.com/payloadcms/payload/security/advisories/GHSA-66wr-7vmr-p5jq
- https://nvd.nist.gov/vuln/detail/CVE-2026-105863
- https://github.com/payloadcms/payload/commit/56cd5cd050a57daebf33159e41e5ff9d4a45239c
- https://github.com/payloadcms/payload/releases/tag/v3.90.0
- https://github.com/advisories/GHSA-66wr-7vmr-p5jq