Description
The client-upload signed-URL endpoints for S3, GCS, Azure, and R2 did not properly sanitize filenames. An attacker could craft filenames to escape the intended storage location.
Recommendation
Update the @payloadcms/storage-gcs package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.78.0
- Patched version(s): 3.78.0
References
Could your website be exposed too?
SmartScanner can check your website for Payload has Insufficient Filename Validation in Client-Upload Signed-URL Endpoints - @payloadcms/storage-gcs and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Payload has Insufficient Filename Validation in Client-Upload Signed-URL Endpoints - @payloadcms/storage-r2 - CVE-2026-34750
- Payload has Insufficient Filename Validation in Client-Upload Signed-URL Endpoints - @payloadcms/storage-azure - CVE-2026-34750
- Payload has Insufficient Filename Validation in Client-Upload Signed-URL Endpoints - CVE-2026-34750
- Payload has Authenticated SSRF via Upload Functionality - CVE-2026-34746


