GHSA-8r29-2mp2-pmrwHigh
Payload Ecommerce has an order confirmation validation issue
🔗 CVE IDs covered (1)
📋 Description
Impact
When using the Stripe payment adapter, an order confirmation could be processed more than once under certain conditions.
You are affected if:
- You use
@payloadcms/plugin-ecommercewith the Stripe payment adapter.
Deployments that do not use the Stripe payment flow are not affected.
Patches
Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Workarounds
Ensure Stripe order confirmations can only be processed once. This is a temporary mitigation; upgrading to a patched version is recommended.
🎯 Affected products2
- npm/@payloadcms/plugin-ecommerce:< 3.90.0
- npm/@payloadcms/plugin-ecommerce:>= 4.0.0-canary.0, < 4.0.0-canary.34