Vulnerability GHSA-8r29-2mp2-pmrw

High Risk
HIGH RISK
CVSS Score: 8.0
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
1 hour ago
October 06, 2026 at 04:17 PM UTC
Payload Ecommerce has an order confirmation validation issue
0.0.1-beta.0 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33
0.0.1-beta.0 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33

Summary

Payload Ecommerce has an order confirmation validation issue

Details

Impact

When using the Stripe payment adapter, an order confirmation could be processed more than once under certain conditions.

You are affected if:

  • You use @payloadcms/plugin-ecommerce with the Stripe payment adapter.

Deployments that do not use the Stripe payment flow are not affected.

Patches

Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.

Workarounds

Ensure Stripe order confirmations can only be processed once. This is a temporary mitigation; upgrading to a patched version is recommended.

Timeline

Published
1 hour ago
October 06, 2026 at 04:17 PM UTC
Fixed (3.90.0)
18 days ago
September 18, 2026 at 02:20 PM UTC
Fixed (4.0.0-canary.34)
18 days ago
September 18, 2026 at 02:28 PM UTC
Last Modified
1 hour ago
October 06, 2026 at 04:30 PM UTC