GHSA-r9v2-gg2j-22q5Medium

Payload: Insufficient Access Control in Stripe REST Proxy

Published
October 6, 2026
Last Modified
October 6, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

An authenticated user could perform unintended Stripe operations through the optional Stripe REST proxy.

You are affected if ALL of these are true:

  • Your application uses @payloadcms/plugin-stripe.
  • The optional Stripe REST proxy is enabled.
  • An authenticated user can reach the proxy.

Deployments that do not enable the Stripe REST proxy are not affected.

Patches

Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.

Workarounds

Upgrading to a patched version is recommended.

If you cannot upgrade immediately, disable the Stripe REST proxy. If it must remain enabled, restrict access to trusted users and only the required Stripe operations.

🎯 Affected products2

  • npm/@payloadcms/plugin-stripe:< 3.90.0
  • npm/@payloadcms/plugin-stripe:>= 4.0.0-canary.0, < 4.0.0-canary.34

🔗 References (4)