{"id":"GHSA-p6mr-xf3r-ghq4","summary":"Payload has a CSRF Protection Bypass in Authentication Flow","details":"### Impact\n\nA Cross-Site Request Forgery (CSRF) vulnerability existed in the authentication flow. Under certain conditions, the configured CSRF protection could be bypassed, allowing cross-site requests to be made.\n\nConsumers are affected if ALL of these are true:\n\n- Payload version **\u003c v3.79.1**\n- `serverURL` is configured\n\n### Patches\n\nThis vulnerability has been patched in **v3.79.1**. Additional validation has been added to the authentication flow.\n\nConsumers should upgrade to **v3.79.1** or later.\n\n### Workarounds\n\nThere is no complete workaround without upgrading. \n\nIf consumers cannot upgrade immediately, setting `cookies.sameSite` to `'Strict'` will prevent the session cookie from being sent cross-site. However, this will also require users to re-authenticate when navigating to the application from external links (e.g. email, other sites).","aliases":["CVE-2026-34749"],"modified":"2026-04-01T21:56:21.133398Z","published":"2026-04-01T21:36:06Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-04-01T21:36:06Z","nvd_published_at":"2026-04-01T20:16:27Z","cwe_ids":["CWE-352"]},"references":[{"type":"WEB","url":"https://github.com/payloadcms/payload/security/advisories/GHSA-p6mr-xf3r-ghq4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34749"},{"type":"PACKAGE","url":"https://github.com/payloadcms/payload"},{"type":"WEB","url":"https://github.com/payloadcms/payload/releases/tag/v3.79.1"}],"affected":[{"package":{"name":"payload","ecosystem":"npm","purl":"pkg:npm/payload"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.79.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-p6mr-xf3r-ghq4/GHSA-p6mr-xf3r-ghq4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"}]}