Vulnerability GHSA-xgv3-crq2-6f69

High Risk
HIGH RISK
CVSS Score: 8.0
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
2 hours ago
October 06, 2026 at 04:17 PM UTC
Payload: Token refresh and password reset responses may expose restricted user fields
3.0.0 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33
3.0.0 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33

Summary

Payload: Token refresh and password reset responses may expose restricted user fields

Details

Impact

Token refresh and password reset responses could return fields that the requesting user did not have access to.

You are affected if:

  • An authentication collection contains hidden or read-restricted fields.

Patches

Authentication responses now apply field access and hidden-field filtering before returning user documents. Full user documents remain available server-side for access control.

Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.

Custom authentication strategies remain responsible for filtering user documents returned through custom responses.

Workarounds

There is no complete workaround. Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.

Impacted packages

Timeline

Published
2 hours ago
October 06, 2026 at 04:17 PM UTC
Fixed (3.90.0)
Unknown
Unknown
Fixed (4.0.0-canary.34)
Unknown
Unknown
Last Modified
1 hour ago
October 06, 2026 at 04:30 PM UTC