GHSA-66wr-7vmr-p5jqCritical

Payload authentication token field handling issue

Published
October 7, 2026
Last Modified
October 7, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

Under certain field configurations, Payload could include unintended values in the authentication token issued at login.

You are affected if:

  • You use an affected Payload version and have configured a custom field option that maps a field to a reserved authentication claim name.

Patches

Payload now restricts which field configuration options can influence the contents of the authentication token.

Users should upgrade payload packages to >= 3.90.0 or >= 4.0.0-canary.34.

Workarounds

There is no complete workaround. Users should upgrade payload packages to >= 3.90.0 or >= 4.0.0-canary.34.

🎯 Affected products2

  • npm/payload:>= 3.0.0, < 3.90.0
  • npm/payload:>= 4.0.0-canary.0, < 4.0.0-canary.34

🔗 References (5)