logo

Database

Prototype Pollution In @payloadcms/plugin-import-export

Description

Payload: Prototype pollution in Payload Import Export plugin

Impact

An unauthenticated user could cause unintended application behavior when the Import Export plugin is enabled, allowing an attacker to submit and execute remote code (RCE).

Applications that do not use @payloadcms/plugin-import-export are not affected.

Patches

Users should upgrade Payload packages to >= 3.88.0 or >= 4.0.0-canary.27.

Workarounds

Upgrading is recommended. Until then, disable the Import Export plugin or restrict access to its endpoints.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions