Simplify your stack and build anything. Or everything.
Build tomorrow’s web with a modern solution you truly own.
Code-based nature means you can build on top of it to power anything.
It’s time to take back your content infrastructure.

Payload Security Update Available for 3.x and 4.0

Payload Security Update
Payload Security Update

Important security updates are now available. Learn which Payload versions are affected and what steps to take to keep your applications secure.

Today we released Payload 3.90.0 and 4.0.0-canary.34, addressing multiple vulnerabilities affecting Payload 3.x and Payload 4.0 canary.

We recommend updating as soon as possible.

The 3.90.0 release notes include the migration steps covering several necessary breaking changes to help you migrate: https://github.com/payloadcms/payload/releases/tag/v3.90.0

Note: the 4.0.0-canary.34 breaking changes and required migration steps are the same.

Security advisories

We have published security advisories alongside the patched releases. Each advisory includes affected versions, severity, impact, and upgrade guidance.

Security in the age of AI-assisted discovery

As every developer is aware, the open-source security landscape is changing fast. Models are getting significantly better at reading code and finding vulnerabilities in it, and OSS naturally sits on the leading edge of that shift. The code is public, so anyone can point these tools at it.

That’s a genuine change in the threat model for every OSS project such as Payload, and we're treating it as one.

We regularly red-team our own codebase, including review of pull requests as they're opened and merged, so issues are caught before they ship rather than after.

Today's release reflects both that work and vulnerabilities reported to us directly by security researchers.

Reporting security issues

We appreciate the researchers and community members who report vulnerabilities responsibly. To report a potential security issue, please contact us directly.

Support and feedback

If you run into problems upgrading or running the migration, please open a GitHub issue. For anything else related to this update or your Payload app, come find us in Discord.