GHSA-pj5h-5q6c-3pfxHigh
Payload external upload trust validation issue
🔗 CVE IDs covered (1)
📋 Description
Impact
Under certain external upload configurations, Payload could send authentication data to a destination that was not verified as trusted. If the affected request contained a valid session, this could expose that session to an unintended recipient.
You are affected if:
- You have enabled external URL-based upload retrieval, where authenticated requests can trigger it.
Patches
Payload now validates the destination before forwarding authentication data and reapplies that validation when a request changes destination.
Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Workarounds
It is recommended to update all Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
If you cannot, a valid workaround exists:
- Disable external URL-based upload retrieval where practical.
- If you cannot disable it, configure the upload header filter to remove authentication data from outbound file requests.
- Restrict access to the affected upload functionality.
🎯 Affected products2
- npm/payload:>= 3.0.0, < 3.90.0
- npm/payload:>= 4.0.0-canary.0, < 4.0.0-canary.34
🔗 References (5)
- https://github.com/payloadcms/payload/security/advisories/GHSA-pj5h-5q6c-3pfx
- https://nvd.nist.gov/vuln/detail/CVE-2026-105861
- https://github.com/payloadcms/payload/commit/ba5cf6ae20d27a2c15106cb37466419031f86e6d
- https://github.com/payloadcms/payload/releases/tag/v3.90.0
- https://github.com/advisories/GHSA-pj5h-5q6c-3pfx