An unauthenticated user could cause unintended application behavior when the Import Export plugin is enabled, allowing an attacker to submit and execute remote code (RCE).
Applications that do not use @payloadcms/plugin-import-export are not affected.
Users should upgrade Payload packages to >= 3.88.0 or >= 4.0.0-canary.27.
Upgrading is recommended. Until then, disable the Import Export plugin or restrict access to its endpoints.
{
"cwe_ids": [
"CWE-1321"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-06T16:09:23Z",
"nvd_published_at": null,
"severity": "CRITICAL"
}