Vulnerability GHSA-qf28-8hc6-vwrp
Critical
CRITICAL RISK
CVSS Score: 9.5
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
2 hours ago
October 06, 2026 at 04:09 PM UTC
Payload: Prototype pollution in Payload Import Export plugin
3.27.0-canary.672dace - 3.87.1 and 4.0.0-canary.1 - 4.0.0-canary.26
3.27.0-canary.672dace - 3.87.1 and 4.0.0-canary.1 - 4.0.0-canary.26
Summary
Payload: Prototype pollution in Payload Import Export plugin
Details
Impact
An unauthenticated user could cause unintended application behavior when the Import Export plugin is enabled, allowing an attacker to submit and execute remote code (RCE).
Applications that do not use @payloadcms/plugin-import-export are not affected.
Patches
Users should upgrade Payload packages to >= 3.88.0 or >= 4.0.0-canary.27.
Workarounds
Upgrading is recommended. Until then, disable the Import Export plugin or restrict access to its endpoints.
Impacted packages
Timeline
Published
2 hours ago
October 06, 2026 at 04:09 PM UTC
Fixed (4.0.0-canary.27)
1 month ago
August 11, 2026 at 08:52 PM UTC
Fixed (3.88.0)
1 month ago
August 11, 2026 at 08:56 PM UTC
Last Modified
2 hours ago
October 06, 2026 at 04:15 PM UTC