GHSA-xgv3-crq2-6f69

Suggest an improvement
Source
https://github.com/advisories/GHSA-xgv3-crq2-6f69
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-xgv3-crq2-6f69/GHSA-xgv3-crq2-6f69.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-xgv3-crq2-6f69
Aliases
Published
2026-10-06T16:17:28Z
Modified
2026-10-06T16:30:04Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Payload: Token refresh and password reset responses may expose restricted user fields
Details

Impact

Token refresh and password reset responses could return fields that the requesting user did not have access to.

You are affected if:

  • An authentication collection contains hidden or read-restricted fields.

Patches

Authentication responses now apply field access and hidden-field filtering before returning user documents. Full user documents remain available server-side for access control.

Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.

Custom authentication strategies remain responsible for filtering user documents returned through custom responses.

Workarounds

There is no complete workaround. Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.

Database specific
{
    "cwe_ids": [
        "CWE-200"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-06T16:17:28Z",
    "nvd_published_at": null,
    "severity": "HIGH"
}
References

Affected packages

npm / payload

Package

Affected ranges

Type
SEMVER
Events
Introduced
3.0.0
Fixed
3.90.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-xgv3-crq2-6f69/GHSA-xgv3-crq2-6f69.json"

npm / payload

Package

Affected ranges

Type
SEMVER
Events
Introduced
4.0.0-canary.0
Fixed
4.0.0-canary.34

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-xgv3-crq2-6f69/GHSA-xgv3-crq2-6f69.json"