Payload: Prototype pollution in Payload Import Export plugin
Critical severity
GitHub Reviewed
Published
Sep 22, 2026
in
payloadcms/payload
•
Updated Oct 6, 2026
Package
Affected versions
>= 3.0.0, < 3.88.0
>= 4.0.0-canary.0, < 4.0.0-canary.27
Patched versions
3.88.0
4.0.0-canary.27
Description
Published to the GitHub Advisory Database
Oct 6, 2026
Reviewed
Oct 6, 2026
Last updated
Oct 6, 2026
Impact
An unauthenticated user could cause unintended application behavior when the Import Export plugin is enabled, allowing an attacker to submit and execute remote code (RCE).
Applications that do not use
@payloadcms/plugin-import-exportare not affected.Patches
Users should upgrade Payload packages to
>= 3.88.0or>= 4.0.0-canary.27.Workarounds
Upgrading is recommended. Until then, disable the Import Export plugin or restrict access to its endpoints.
References