Listen to this Post
Payload is a free and open source headless content management system.
In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34,
token refresh responses and password reset responses can independently return
hidden or read-restricted fields that the requesting user cannot access.
This occurs because authentication responses did not apply field-level access
control or hidden-field filtering before returning user documents.
An authentication collection may define fields with hidden: true or
access: { read: … } restrictions.
When a user refreshes their token or resets their password,
the server returns the full user document including those restricted fields.
An attacker with a low-privileged account can trigger these endpoints
and receive sensitive data such as password hashes, reset tokens,
or other private fields.
The vulnerability is classified as CWE-200: Exposure of Sensitive Information
to an Unauthorized Actor.
The CVSS v4.0 base score is 7.1, rated as High severity.
Attack vector is Network, attack complexity is Low,
privileges required are Low, and no user interaction is needed.
The issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Patches now apply field access and hidden-field filtering
before returning user documents in authentication responses.
Full user documents remain available server-side for access control.
Custom authentication strategies remain responsible for filtering
user documents returned through custom responses.
There is no complete workaround; users must upgrade.
The vulnerability was published on 2026-09-18 and reviewed on 2026-10-06.
It affects the payload package on npm.
The advisory is GHSA-xgv3-crq2-6f69.
This information disclosure can lead to further attacks
such as account takeover if reset tokens are exposed.
DailyCVE Form:
Platform: Payload
Version: 3.0.0-3.89.0
Vulnerability: Information Disclosure
Severity: High
date: 2026-09-18
Prediction: 2026-09-18
What Undercode Say:
Analytics
Check installed Payload version npm list payload or cat package.json | grep '"payload"'
Test token refresh endpoint curl -X POST https://example.com/api/users/refresh-token \ -H "Authorization: Bearer <user_token>" \ -H "Content-Type: application/json"
Test password reset endpoint
curl -X POST https://example.com/api/users/forgot-password \
-H "Content-Type: application/json" \
-d '{"email":"[email protected]"}'
// Payload local API example (server-side) that bypasses field access
const user = await payload.findByID({
collection: 'users',
id: userId,
overrideAccess: true, // returns all fields
});
console.log(user);
How Exploit: (Educational Purposes!)
An attacker with a valid low-privileged account can call the refresh token
or password reset endpoints. The response may include fields that are
normally hidden or read-restricted. By inspecting the JSON response,
the attacker can extract sensitive information.
Protection: from this CVE
Upgrade Payload to version 3.90.0 or later, or 4.0.0-canary.34 or later.
Apply field-level access control and hidden-field filtering
in custom authentication strategies.
Monitor for unusual token refresh or password reset requests.
Impact:
Token refresh and password reset responses could return fields
that the requesting user did not have access to.
This leads to exposure of sensitive user data,
potentially enabling account takeover or privilege escalation.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

