Executive brief
Payload is a content management system and backend framework. A CSRF (cross-site request forgery) vulnerability in its authentication flow allows attackers to bypass configured security protections under certain conditions, potentially enabling unauthorized actions on behalf of authenticated users. Affected applications must have serverURL configured to be at risk.
Technical details
The vulnerability is a Cross-Site Request Forgery (CSRF) in the authentication flow (CWE-352) where configured CSRF protections could be bypassed under certain conditions, allowing attackers to forge cross-site requests. The vulnerability requires no privileges and is exploitable over the network, but does require user interaction (e.g., a user visiting a malicious site while authenticated). Exploitation affects applications running Payload versions prior to 3.79.1 where serverURL is configured. The impact is limited to integrity and availability (no confidentiality loss). Payload has patched the issue in v3.79.1 by adding additional validation to the authentication flow; users should upgrade immediately. A temporary mitigation without upgrading is to set cookies.sameSite to 'Strict', though this degrades user experience by requiring re-authentication from external links.
Affected products
- Payload Payload < 3.79.1
Timeline
- 2026-04-01: advisory: Security advisory published
- 2026-04-01: patched: Patch released in v3.79.1