Vulnerability GHSA-2q76-m6w6-qgc6

High Risk
HIGH RISK
CVSS Score: 8.0
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
2 hours ago
October 06, 2026 at 04:09 PM UTC
Payload: Improper access control for MCP API keys
3.61.0 - 3.87.1
3.61.0 - 3.87.1

Summary

Payload: Improper access control for MCP API keys

Details

Impact

Under certain conditions, an authenticated user could manage MCP API keys outside their intended account allowing an attacker to escalate privileges through account takeover.

Applications that do not use @payloadcms/plugin-mcp are not affected.

Patches

Users should upgrade to @payloadcms/plugin-mcp version 3.88.0 or later.

Workarounds

Upgrading is recommended. Until then, disable the MCP plugin or restrict MCP API-key management to trusted users.

Impacted packages

Timeline

Published
2 hours ago
October 06, 2026 at 04:09 PM UTC
Fixed (3.88.0)
1 month ago
August 11, 2026 at 08:56 PM UTC
Last Modified
2 hours ago
October 06, 2026 at 04:15 PM UTC