Impact
The vulnerability resides in the Stripe REST proxied endpoint of Payload CMS. An authenticated user who can reach the optional Stripe REST proxy can execute unintended Stripe operations because the proxy fails to enforce proper authorization checks. This type of flaw corresponds to CWE‑749 (Inverted Conditional) and CWE‑862 (Missing Authorization), allowing the attacker to exceed their intended privileges and perform financial or data actions against Stripe accounts.
Affected Systems
Affected systems include Payload CMS and its Stripe plugin. Versions of @payloadcms/plugin‑stripe prior to 3.90.0, as well as the canary channel before 4.0.0‑canary.34, are compromised. The issue also impacts the @payloadcms/payload platform when the Stripe plugin is enabled. Updating to version 3.90.0 or later, or the 4.0.0‑canary.34 release, removes the vulnerability.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity. The EPSS score is not available, so the likelihood of exploitation cannot be quantified from the provided data. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector requires authentication and network reachability to the optional Stripe REST proxy endpoint. Once that condition is met, the attacker can trigger any Stripe operation exposed by the proxy, potentially leading to unauthorized charges, refunds, or data exposure.
OpenCVE Enrichment
Github GHSA