GHSA-8r29-2mp2-pmrwHigh

Payload Ecommerce has an order confirmation validation issue

Published
October 6, 2026
Last Modified
October 6, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

When using the Stripe payment adapter, an order confirmation could be processed more than once under certain conditions.

You are affected if:

  • You use @payloadcms/plugin-ecommerce with the Stripe payment adapter.

Deployments that do not use the Stripe payment flow are not affected.

Patches

Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.

Workarounds

Ensure Stripe order confirmations can only be processed once. This is a temporary mitigation; upgrading to a patched version is recommended.

🎯 Affected products2

  • npm/@payloadcms/plugin-ecommerce:< 3.90.0
  • npm/@payloadcms/plugin-ecommerce:>= 4.0.0-canary.0, < 4.0.0-canary.34

🔗 References (4)