Please report any security issues or concerns to security@payloadcms.com.
Repository navigation
Security: payloadcms/payload
Security
SECURITY.md
-
Access control bypass of uploads in Vercel Storage adapterGHSA-mc8m-rr6c-r5qr published
Sep 25, 2026 by DanRibbensModerate -
Password hashes use insufficient PBKDF2 iterationsGHSA-q6mq-ch85-c8mm published
Sep 29, 2026 by DanRibbensModerate -
Hidden-field leak in MCP login responsesGHSA-jjm7-864w-gg8q published
Oct 6, 2026 by DanRibbensHigh -
Account takeover through MCP password recoveryGHSA-h5rh-4jwf-738p published
Oct 6, 2026 by DanRibbensHigh -
Access bypass of Payload JobsGHSA-2qw6-cm49-277x published
Oct 6, 2026 by DanRibbensHigh -
Untrusted redirect URL parameter exploitGHSA-w84c-53h3-mc2g published
Sep 22, 2026 by DanRibbensModerate -
Sort queries could expose protected field informationGHSA-9g87-32v6-3c2r published
Sep 22, 2026 by DanRibbensModerate -
Improper access control for MCP API keysGHSA-2q76-m6w6-qgc6 published
Sep 22, 2026 by DanRibbensHigh -
Prototype pollution in Payload Import Export pluginGHSA-qf28-8hc6-vwrp published
Sep 22, 2026 by DanRibbensCritical -
SQL Injection in SQLite and PostgresGHSA-v49j-62m6-pgrr published
Sep 22, 2026 by DanRibbensCritical
Learn more about advisories related to payloadcms/payload in the GitHub Advisory Database