GHSA-fpww-c55p-cjv6High

Payload: Polymorphic join queries could disclose hidden fields

Published
October 6, 2026
Last Modified
October 6, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

A user with query access could use polymorphic join filters to infer hidden or read-restricted field values, including password-reset tokens.

You are affected if:

  • You use an affected Payload version.
  • Users can query a collection with a polymorphic join to sensitive fields.

Patches

Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.

Workarounds

There is no complete workaround. Restricting read access to sensitive collections reduces exposure but does not replace upgrading.

🎯 Affected products2

  • npm/payload:>= 3.0.0, < 3.90.0
  • npm/payload:>= 4.0.0-canary.0, < 4.0.0-canary.34

🔗 References (4)