Vulnerability GHSA-4ww4-68q3-h7g5
Summary
Payload: Field-level write access bypass in Payload on MongoDB
Details
Impact
A vulnerability in field-level access control could allow an authenticated user to modify fields they are not permitted to change on documents they can otherwise update.
You are affected if: Payload version < 3.87.0 (or a 4.0.0-canary release before 4.0.0-canary.20) using the MongoDB adapter (@payloadcms/db-mongodb) with any collection that relies on field-level access control to restrict writes under certain conditions.
Relational adapters (Postgres, SQLite) are not affected.
Patches
Handling of incoming field data has been hardened so field-level access control is enforced consistently.
Users should upgrade to 3.87.0 (or 4.0.0-canary.20 on the 4.x line) or later.
Workarounds
There is no complete workaround. Upgrading to 3.87.0 (or 4.0.0-canary.20 on the 4.x line) is recommended.