GHSA-8r29-2mp2-pmrw

Suggest an improvement
Source
https://github.com/advisories/GHSA-8r29-2mp2-pmrw
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-8r29-2mp2-pmrw/GHSA-8r29-2mp2-pmrw.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-8r29-2mp2-pmrw
Aliases
  • CVE-2026-105850
Published
2026-10-06T16:17:54Z
Modified
2026-10-06T16:30:04Z
Severity
  • 8.8 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Payload Ecommerce has an order confirmation validation issue
Details

Impact

When using the Stripe payment adapter, an order confirmation could be processed more than once under certain conditions.

You are affected if:

  • You use @payloadcms/plugin-ecommerce with the Stripe payment adapter.

Deployments that do not use the Stripe payment flow are not affected.

Patches

Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.

Workarounds

Ensure Stripe order confirmations can only be processed once. This is a temporary mitigation; upgrading to a patched version is recommended.

Database specific
{
    "cwe_ids":  [
        "CWE-837"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-10-06T16:17:54Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

npm / @payloadcms/plugin-ecommerce

Package

Name
@payloadcms/plugin-ecommerce
View open source insights on deps.dev
Purl
pkg:npm/%40payloadcms/plugin-ecommerce

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.90.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-8r29-2mp2-pmrw/GHSA-8r29-2mp2-pmrw.json"

npm / @payloadcms/plugin-ecommerce

Package

Name
@payloadcms/plugin-ecommerce
View open source insights on deps.dev
Purl
pkg:npm/%40payloadcms/plugin-ecommerce

Affected ranges

Type
SEMVER
Events
Introduced
4.0.0-canary.0
Fixed
4.0.0-canary.34

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-8r29-2mp2-pmrw/GHSA-8r29-2mp2-pmrw.json"