{"id":"GHSA-65w6-pf7x-5g85","summary":"@delmaredigital/payload-puc is missing authorization on /api/puck/* CRUD endpoints allows unauthenticated access to Puck-registered collections","details":"### Impact\n\nAll `/api/puck/*` CRUD endpoint handlers registered by `createPuckPlugin()` called Payload's local API with the default `overrideAccess: true`, bypassing all collection-level access control. The `access` option passed to `createPuckPlugin()` and any `access` rules defined on Puck-registered collections were silently ignored on these endpoints.\n\nAn unauthenticated remote attacker could:\n\n- List all documents (including drafts) in any Puck-registered collection\n- Read any document by ID (including drafts)\n- Create new documents with arbitrary field values\n- Update any document (including bypassing field-level access rules)\n- Delete any document\n- Read version history and restore arbitrary versions\n\n**In typical installations**, the affected scope is the collection backing the website's pages (default slug: `pages`). For most users this means an attacker could read, modify, create, or delete every page on the website — including unpublished drafts and version history.\n\n**Scope is limited to collections explicitly registered with `createPuckPlugin()`** — the endpoints validate the collection slug against an allowlist, so attackers cannot pivot to other Payload collections such as `users`, `media`, or business data not exposed to the plugin. The auto-created `puck-templates`, `puck-ai-prompts`, and `puck-ai-context` collections are also outside the allowlist; they have their own dedicated endpoints with separate authentication.\n\nOther endpoints in the plugin (AI, styles, prompts, context, and the Next.js API route factories in `src/api/`) were unaffected — they had their own authentication checks.\n\n### Patches\n\nFixed in **0.6.23**. All endpoint handlers in `src/endpoints/index.ts` now pass `overrideAccess: false` and forward `req` to Payload's local API, so collection-level access rules are evaluated against the current user.\n\n### Workarounds\n\nIf you cannot upgrade immediately, place a reverse-proxy or middleware authentication check in front of `/api/puck/*` to require an authenticated session before requests reach the plugin's handlers.","aliases":["CVE-2026-39397"],"modified":"2026-04-08T00:56:21.663581Z","published":"2026-04-08T00:15:54Z","database_specific":{"nvd_published_at":"2026-04-07T21:17:18Z","cwe_ids":["CWE-862"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-04-08T00:15:54Z"},"references":[{"type":"WEB","url":"https://github.com/delmaredigital/payload-puck/security/advisories/GHSA-65w6-pf7x-5g85"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-39397"},{"type":"WEB","url":"https://github.com/delmaredigital/payload-puck/issues/7"},{"type":"WEB","url":"https://github.com/delmaredigital/payload-puck/commit/9148201c6bbfa140d44546438027a2f8a70f79a4"},{"type":"PACKAGE","url":"https://github.com/delmaredigital/payload-puck"}],"affected":[{"package":{"name":"@delmaredigital/payload-puck","ecosystem":"npm","purl":"pkg:npm/%40delmaredigital/payload-puck"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.6.23"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-65w6-pf7x-5g85/GHSA-65w6-pf7x-5g85.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L"}]}