Payload is a free and open source headless content management system. Prior to version 3.79.1 in @payloadcms/graphql and payload, a vulnerability in the password recovery flow could allow an unauthenticated attacker to perform actions on behalf of a user who initiates a password reset. This issue has been patched in version 3.79.1 for @payloadcms/graphql and payload.
The vulnerability affects the password recovery flow (CWE-640) and improper authentication parameter management (CWE-472). An attacker without any privileges can abuse the password reset process initiated by a victim and take control of their session or perform actions on their behalf. The vulnerability does not require interaction from the attacker beyond the reset flow — it is sufficient that a legitimate user initiates the password recovery procedure.
An attacker can gain unauthorized access to a user account and modify data or content managed by Payload CMS on behalf of the victim, leading to a breach of data confidentiality and integrity.
Update the @payloadcms/graphql and payload packages to version 3.79.1 or newer, where the vulnerability has been removed. Details are available in the vendor references on GitHub.
The @payloadcms/graphql and payload packages in all versions prior to 3.79.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NPayloadcms Payload
APPPayloadcms< 3.79.1
Related vulnerabilities
SQL Injection w Payload CMS — przejęcie konta bez uwierzytelnienia
PayloadCMS: RCE poprzez nieograniczony upload pliku SVG
Payload is a free and open source headless content management system. Prior to version 3.79.1, an authenticate...
Payload is a free and open source headless content management system. Prior to version 3.79.1, certain request...
Payload is a free and open source headless content management system. Prior to version 3.78.0 in @payloadcms/n...