Vulnerability GHSA-8r29-2mp2-pmrw
High Risk
HIGH RISK
CVSS Score: 8.0
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
1 hour ago
October 06, 2026 at 04:17 PM UTC
Payload Ecommerce has an order confirmation validation issue
0.0.1-beta.0 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33
0.0.1-beta.0 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33
Summary
Payload Ecommerce has an order confirmation validation issue
Details
Impact
When using the Stripe payment adapter, an order confirmation could be processed more than once under certain conditions.
You are affected if:
- You use
@payloadcms/plugin-ecommercewith the Stripe payment adapter.
Deployments that do not use the Stripe payment flow are not affected.
Patches
Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Workarounds
Ensure Stripe order confirmations can only be processed once. This is a temporary mitigation; upgrading to a patched version is recommended.
Impacted packages
Timeline
Published
1 hour ago
October 06, 2026 at 04:17 PM UTC
Fixed (3.90.0)
18 days ago
September 18, 2026 at 02:20 PM UTC
Fixed (4.0.0-canary.34)
18 days ago
September 18, 2026 at 02:28 PM UTC
Last Modified
1 hour ago
October 06, 2026 at 04:30 PM UTC