Vulnerability GHSA-7c34-32v3-j575

Medium Risk
MEDIUM RISK
CVSS Score: 6.0
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
1 hour ago
October 06, 2026 at 04:17 PM UTC
Payload relationship-query authorization bypass
0.1.137 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33
0.1.137 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33

Summary

Payload relationship-query authorization bypass

Details

Impact

A readable collection could expose information about protected documents in a related collection.

You are affected if:

  • You expose a readable collection with a relationship to a collection protected by access.read where constraints.

Patches

Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.

Workarounds

There is no complete workaround. Upgrade Payload packages >= 3.90.0 or >= 4.0.0-canary.34.

Impacted packages

Timeline

Published
1 hour ago
October 06, 2026 at 04:17 PM UTC
Fixed (3.90.0)
Unknown
Unknown
Fixed (4.0.0-canary.34)
Unknown
Unknown
Last Modified
1 hour ago
October 06, 2026 at 04:30 PM UTC