GHSA-2q76-m6w6-qgc6

Suggest an improvement
Source
https://github.com/advisories/GHSA-2q76-m6w6-qgc6
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-2q76-m6w6-qgc6/GHSA-2q76-m6w6-qgc6.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-2q76-m6w6-qgc6
Aliases
Published
2026-10-06T16:09:31Z
Modified
2026-10-06T16:15:05Z
Severity
  • 8.6 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Payload: Improper access control for MCP API keys
Details

Impact

Under certain conditions, an authenticated user could manage MCP API keys outside their intended account allowing an attacker to escalate privileges through account takeover.

Applications that do not use @payloadcms/plugin-mcp are not affected.

Patches

Users should upgrade to @payloadcms/plugin-mcp version 3.88.0 or later.

Workarounds

Upgrading is recommended. Until then, disable the MCP plugin or restrict MCP API-key management to trusted users.

Database specific
{
    "cwe_ids": [
        "CWE-862"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-06T16:09:31Z",
    "nvd_published_at": null,
    "severity": "HIGH"
}
References

Affected packages

npm / @payloadcms/plugin-mcp

Package

Name
@payloadcms/plugin-mcp
View open source insights on deps.dev
Purl
pkg:npm/%40payloadcms/plugin-mcp

Affected ranges

Type
SEMVER
Events
Introduced
3.61.0
Fixed
3.88.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-2q76-m6w6-qgc6/GHSA-2q76-m6w6-qgc6.json"