GHSA-9g87-32v6-3c2rMedium

Payload: Sort queries could expose protected field information

Published
October 6, 2026
Last Modified
October 6, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

Under certain conditions, sorting readable records could reveal limited information about fields the requester was not permitted to read.

You are affected if untrusted users can query a collection, control its sorting, and sort by protected fields.

Patches

Payload now applies field-level access checks to sort fields before executing queries.

Users should upgrade to >= 3.88.0 or >= 4.0.0-canary.27.

Workarounds

Upgrading is recommended. Until then, prevent untrusted users from controlling sort parameters or restrict their access to affected collections.

🎯 Affected products2

  • npm/payload:< 3.88.0
  • npm/payload:>= 4.0.0-canary.0, < 4.0.0-canary.27

🔗 References (4)