Vulnerabilities/

Payload: Pre-Authentication Account Takeover via Parameter Injection in Password Recovery

Severity:
High

Description

A vulnerability in the password recovery flow could allow an unauthenticated attacker to perform actions on behalf of a user who initiates a password reset.

Recommendation

Update the @payloadcms/graphql package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@payloadcms/graphql
Anything's wrong? Let us know Last updated on April 08, 2026