Vulnerabilities/

Payload has Authenticated SSRF via Upload Functionality

Severity:
High

Description

An authenticated Server-Side Request Forgery (SSRF) vulnerability existed in the upload functionality.

Authenticated users with create or update access to an upload-enabled collection could cause the server to make outbound HTTP requests to arbitrary URLs.

Recommendation

Update the payload package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
payload
Anything's wrong? Let us know Last updated on April 06, 2026