GHSA-r9v2-gg2j-22q5Medium
Payload: Insufficient Access Control in Stripe REST Proxy
🔗 CVE IDs covered (1)
📋 Description
Impact
An authenticated user could perform unintended Stripe operations through the optional Stripe REST proxy.
You are affected if ALL of these are true:
- Your application uses
@payloadcms/plugin-stripe. - The optional Stripe REST proxy is enabled.
- An authenticated user can reach the proxy.
Deployments that do not enable the Stripe REST proxy are not affected.
Patches
Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Workarounds
Upgrading to a patched version is recommended.
If you cannot upgrade immediately, disable the Stripe REST proxy. If it must remain enabled, restrict access to trusted users and only the required Stripe operations.
🎯 Affected products2
- npm/@payloadcms/plugin-stripe:< 3.90.0
- npm/@payloadcms/plugin-stripe:>= 4.0.0-canary.0, < 4.0.0-canary.34