Vulnerability GHSA-fpww-c55p-cjv6

High Risk
HIGH RISK
CVSS Score: 8.0
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
2 hours ago
October 06, 2026 at 04:09 PM UTC
Payload: Polymorphic join queries could disclose hidden fields
3.0.0 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33
3.0.0 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33

Summary

Payload: Polymorphic join queries could disclose hidden fields

Details

Impact

A user with query access could use polymorphic join filters to infer hidden or read-restricted field values, including password-reset tokens.

You are affected if:

  • You use an affected Payload version.
  • Users can query a collection with a polymorphic join to sensitive fields.

Patches

Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.

Workarounds

There is no complete workaround. Restricting read access to sensitive collections reduces exposure but does not replace upgrading.

Impacted packages

Timeline

Published
2 hours ago
October 06, 2026 at 04:09 PM UTC
Fixed (3.90.0)
Unknown
Unknown
Fixed (4.0.0-canary.34)
Unknown
Unknown
Last Modified
2 hours ago
October 06, 2026 at 04:15 PM UTC