Vulnerability GHSA-238x-w2j9-gwwr
High Risk
HIGH RISK
CVSS Score: 8.0
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
2 hours ago
October 06, 2026 at 04:18 PM UTC
Payload vulnerable to API key disclosure through ordinary document reads
3.0.0 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33
3.0.0 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33
Summary
Payload vulnerable to API key disclosure through ordinary document reads
Details
Impact
Users with read access to other user documents could access their active API keys. An exposed key grants the target account’s permissions until rotated or disabled.
You are affected if:
- An authentication collection enables
useAPIKey. - Users have read access to other user documents containing active API keys.
Patches
Users should upgrade payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Workarounds
Disable useAPIKey or restrict users to reading only their own authentication document. Rotate any API key that may have been exposed.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
2 hours ago
Payload didn't enforce field-level password update restrictions
0.1.137 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33 GHSA-fx49-4h83-wjv9
0.1.137 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33 GHSA-fx49-4h83-wjv9
High Risk
2 hours ago
Payload: ReDoS in Multipart Content-Type Validation
3.0.0 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33 GHSA-2g7p-5934-q4w7
3.0.0 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33 GHSA-2g7p-5934-q4w7
Medium Risk
2 hours ago
Payload relationship-query authorization bypass
0.1.137 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33 GHSA-7c34-32v3-j575
0.1.137 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33 GHSA-7c34-32v3-j575
High Risk
2 hours ago
Payload: Token refresh and password reset responses may expose restricted user fields
3.0.0 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33 GHSA-xgv3-crq2-6f69
3.0.0 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33 GHSA-xgv3-crq2-6f69
Critical
2 hours ago
Payload: SQL Injection in SQLite and Postgres
3.0.0 - 3.87.1 and 4.0.0-canary.0 - 4.0.0-canary.26 GHSA-v49j-62m6-pgrr
3.0.0 - 3.87.1 and 4.0.0-canary.0 - 4.0.0-canary.26 GHSA-v49j-62m6-pgrr
Impacted packages
Timeline
Published
2 hours ago
October 06, 2026 at 04:18 PM UTC
Fixed (3.90.0)
Unknown
Unknown
Fixed (4.0.0-canary.34)
Unknown
Unknown
Last Modified
2 hours ago
October 06, 2026 at 04:30 PM UTC