VDB
Sign up
CRITICAL9.1

GHSA-hp5w-3hxx-vmwf

Payload: Pre-Authentication Account Takeover via Parameter Injection in Password Recovery

Quick fix

GHSA-hp5w-3hxx-vmwf — payload: upgrade to the fixed version with the command below.

npm install payload@3.79.1

Details

### Impact

A vulnerability in the password recovery flow could allow an unauthenticated attacker to perform actions on behalf of a user who initiates a password reset.

Users are affected if:

- They are using Payload version **< v3.79.1** with any auth-enabled collection using the built-in `forgot-password` functionality.

### Patches

Input validation and URL construction in the password recovery flow have been hardened.

Users should upgrade to **v3.79.1** or later.

### Workarounds

There are no complete workarounds. Upgrading to **v3.79.1** is recommended.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/payload
Introduced in: 0Fixed in: 3.79.1
Fixnpm install payload@3.79.1
npm/@payloadcms/graphql
Introduced in: 0Fixed in: 3.79.1
Fixnpm install @payloadcms/graphql@3.79.1

References