Executive brief
@payloadcms/next is a headless CMS framework used to build admin interfaces and manage content. A stored cross-site scripting vulnerability in the admin panel allows authenticated users with write access to versioned collections to inject malicious JavaScript that executes when other users view that content, potentially leading to account compromise or data theft.
Technical details
The vulnerability is a stored XSS (CWE-79) in the admin panel of @payloadcms/next versions before 3.78.0. An authenticated user with create or update permissions on a collection with versioning enabled can save malicious JavaScript in content fields. When another user views this content, the unencoded output allows the script to execute in their browser context, potentially granting access to sensitive data or admin functionality. The attack requires network access, valid credentials, and user interaction (victim viewing the affected content). The fix involves adding output encoding to prevent user-supplied content from being interpreted as markup. Patch is available in v3.78.0 and later.
Affected products
- Payload @payloadcms/next < 3.78.0
Timeline
- 2026-04-01: disclosed: GHSA-mmxc-95ch-2j7c published
- 2026-03-30: patched: Patch released in v3.78.0