UNKNOWNCVE-2026-34751

Payload has Unvalidated Input in Password Recovery Endpoints

Platform

nodejs

Component

@payloadcms/graphql

Fixed in

3.79.1

Payload is a free and open source headless content management system. Prior to version 3.79.1 in @payloadcms/graphql and payload, a vulnerability in the password recovery flow could allow an unauthenticated attacker to perform actions on behalf of a user who initiates a password reset. This issue has been patched in version 3.79.1 for @payloadcms/graphql and payload.

How to fix

Actualice Payload CMS GraphQL a la versión 3.79.1 o superior. Esta versión contiene una corrección para la vulnerabilidad de recuperación de contraseñas. La actualización se puede realizar a través del gestor de paquetes npm.

Monitor your dependencies automatically

Get notified when new vulnerabilities affect your projects. Free forever.

Start free