Prototype Pollution In @payloadcms/plugin-import-export
Description
Payload: Prototype pollution in Payload Import Export plugin
Impact
An unauthenticated user could cause unintended application behavior when the Import Export plugin is enabled, allowing an attacker to submit and execute remote code (RCE).
Applications that do not use @payloadcms/plugin-import-export are not affected.
Patches
Users should upgrade Payload packages to >= 3.88.0 or >= 4.0.0-canary.27.
Workarounds
Upgrading is recommended. Until then, disable the Import Export plugin or restrict access to its endpoints.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
npm | 3.88.0, 4.0.0-canary.27 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3. 4.