Disclosure summary
## Impact Under certain external upload configurations, Payload could send authentication data to a destination that was not verified as trusted. If the affected request contained a valid session, this could expose that session to an unintended recipient. **You are affected if:** - You have enabled external URL-based upload retrieval, where authenticated requests can trigger it. ## Patches Payload now validates the destination before forwarding authentication data and reapplies that validation when a request changes destination. Users should upgrade Payload packages to `>= 3.90.0` or `>= 4.0.0-canary.34`. ## Workarounds It is recommended to update all Payload packages to `>= 3.90.0` or `>= 4.0.0-canary.34`. If you cannot, a valid workaround exists: - Disable external URL-based upload retrieval where practical. - If you cannot disable it, configure the upload header filter to remove authentication data from outbound file requests. - Restrict access to the affected upload functionality.
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-pj5h-5q6c-3pfx
Open original source · Updated Oct 07, 2026
Payload external upload trust validation issue
Source severity: HIGH / 7.2
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| npm | payload | >= 3.0.0, < 3.90.0 | 3.90.0 |
| npm | payload | >= 4.0.0-canary.0, < 4.0.0-canary.34 | 4.0.0-canary.34 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-07T16:29:41-04:00
MODIFIED 2026-10-07T16:29:42-04:00
INGESTED 2026-10-08T12:30:39-04:00