GHSA-qf28-8hc6-vwrpCritical
Payload: Prototype pollution in Payload Import Export plugin
🔗 CVE IDs covered (1)
📋 Description
Impact
An unauthenticated user could cause unintended application behavior when the Import Export plugin is enabled, allowing an attacker to submit and execute remote code (RCE).
Applications that do not use @payloadcms/plugin-import-export are not affected.
Patches
Users should upgrade Payload packages to >= 3.88.0 or >= 4.0.0-canary.27.
Workarounds
Upgrading is recommended. Until then, disable the Import Export plugin or restrict access to its endpoints.
🎯 Affected products2
- npm/@payloadcms/plugin-import-export:>= 3.0.0, < 3.88.0
- npm/@payloadcms/plugin-import-export:>= 4.0.0-canary.0, < 4.0.0-canary.27