Improper authorization control for web services In @payloadcms/plugin-mcp
Description
Payload: Improper access control for MCP API keys
Impact
Under certain conditions, an authenticated user could manage MCP API keys outside their intended account allowing an attacker to escalate privileges through account takeover.
Applications that do not use @payloadcms/plugin-mcp are not affected.
Patches
Users should upgrade to @payloadcms/plugin-mcp version 3.88.0 or later.
Workarounds
Upgrading is recommended. Until then, disable the MCP plugin or restrict MCP API-key management to trusted users.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
npm | 3.88.0 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3.