HIGH 7.7 npm

Payload has Authenticated SSRF via Upload Functionality

GHSA-6r7f-q7f5-wpx8 · CVE-2026-34746

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Impact

An authenticated Server-Side Request Forgery (SSRF) vulnerability existed in the upload functionality.

Authenticated users with create or update access to an upload-enabled collection could cause the server to make outbound HTTP requests to arbitrary URLs.

Consumers are affected if ALL of these are true:

  • Payload version < v3.79.1
  • At least one collection with upload enabled
  • An authenticated user has create or update access to that collection

Patches

This vulnerability has been patched in v3.79.1. Users should upgrade to v3.79.1 or later.

Workarounds

Until consumers can upgrade:

  • Restrict create and update access to upload-enabled collections to trusted roles only.
  • Limit outbound network access from your Payload server where possible.

Ready to move

Start Securing

Free, no credit card | First findings in minutes