GHSA-pj5h-5q6c-3pfxHigh

Payload external upload trust validation issue

Published
October 7, 2026
Last Modified
October 7, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

Under certain external upload configurations, Payload could send authentication data to a destination that was not verified as trusted. If the affected request contained a valid session, this could expose that session to an unintended recipient.

You are affected if:

  • You have enabled external URL-based upload retrieval, where authenticated requests can trigger it.

Patches

Payload now validates the destination before forwarding authentication data and reapplies that validation when a request changes destination.

Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.

Workarounds

It is recommended to update all Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.

If you cannot, a valid workaround exists:

  • Disable external URL-based upload retrieval where practical.
  • If you cannot disable it, configure the upload header filter to remove authentication data from outbound file requests.
  • Restrict access to the affected upload functionality.

🎯 Affected products2

  • npm/payload:>= 3.0.0, < 3.90.0
  • npm/payload:>= 4.0.0-canary.0, < 4.0.0-canary.34

🔗 References (5)