Impact
Token refresh and password reset responses in PayloadCMS may return hidden or read‑restricted user fields that the requesting user cannot normally see, exposing sensitive data to unauthorized actors. This is an information disclosure vulnerability as defined by CWE‑200, which can compromise user confidentiality and potentially reveal data that should be protected by role‑based access controls.
Affected Systems
PayloadCMS systems running the Payload component are affected. All releases from version 3.0.0 up through the last release prior to 3.90.0, as well as canary releases before 4.0.0‑canary.34, contain the issue. Versions 3.90.0 and 4.0.0‑canary.34 or later have the fix and are not vulnerable.
Risk and Exploitability
The vulnerability scores a CVSS of 7.1, reflecting a medium to high severity. The issue is not listed in the CISA KEV catalog, so the exploitation likelihood is uncertain. The likely attack vector is remote over the network via the standard web API; an attacker who can invoke a token‑refresh or password‑reset operation can retrieve unauthorized user information, potentially facilitating further credential or privilege escalation.
OpenCVE Enrichment
Github GHSA