Impact
A user with query access could use polymorphic join filters to infer hidden or read-restricted field values, including password-reset tokens.
You are affected if:
- You use an affected Payload version.
- Users can query a collection with a polymorphic join to sensitive fields.
Patches
Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Workarounds
There is no complete workaround. Restricting read access to sensitive collections reduces exposure but does not replace upgrading.
Impact
A user with query access could use polymorphic join filters to infer hidden or read-restricted field values, including password-reset tokens.
You are affected if:
Patches
Users should upgrade Payload packages to
>= 3.90.0or>= 4.0.0-canary.34.Workarounds
There is no complete workaround. Restricting read access to sensitive collections reduces exposure but does not replace upgrading.