GHSA-qf28-8hc6-vwrpCritical

Payload: Prototype pollution in Payload Import Export plugin

Published
October 6, 2026
Last Modified
October 6, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

An unauthenticated user could cause unintended application behavior when the Import Export plugin is enabled, allowing an attacker to submit and execute remote code (RCE).

Applications that do not use @payloadcms/plugin-import-export are not affected.

Patches

Users should upgrade Payload packages to >= 3.88.0 or >= 4.0.0-canary.27.

Workarounds

Upgrading is recommended. Until then, disable the Import Export plugin or restrict access to its endpoints.

🎯 Affected products2

  • npm/@payloadcms/plugin-import-export:>= 3.0.0, < 3.88.0
  • npm/@payloadcms/plugin-import-export:>= 4.0.0-canary.0, < 4.0.0-canary.27

🔗 References (4)