An authenticated user could perform unintended Stripe operations through the optional Stripe REST proxy.
You are affected if ALL of these are true:
@payloadcms/plugin-stripe.Deployments that do not enable the Stripe REST proxy are not affected.
Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Upgrading to a patched version is recommended.
If you cannot upgrade immediately, disable the Stripe REST proxy. If it must remain enabled, restrict access to trusted users and only the required Stripe operations.
{
"cwe_ids": [
"CWE-749",
"CWE-862"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-06T16:09:46Z",
"nvd_published_at": null,
"severity": "MODERATE"
}