Vulnerabilities/

Payload has a CSRF Protection Bypass in Authentication Flow

Severity:
Medium

Description

A Cross-Site Request Forgery (CSRF) vulnerability existed in the authentication flow. Under certain conditions, the configured CSRF protection could be bypassed, allowing cross-site requests to be made.

Recommendation

Update the payload package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
payload
Anything's wrong? Let us know Last updated on April 01, 2026