Simplify your stack and build anything. Or everything.
Build tomorrow’s web with a modern solution you truly own.
Code-based nature means you can build on top of it to power anything.
It’s time to take back your content infrastructure.

New in Payload: Security Dependency Bumps and Fixes

New in Payload: Release v3.87.1
New in Payload: Release v3.87.1

Payload 3.87.1 bumps mongoose, undici, and the MCP SDK to resolve upstream security advisories, and fixes dev-server HMR, rich text link drawers, and the Cloudflare D1 template.

Highlights

This patch release pulls in security fixes from upstream dependencies — bumping mongoose, undici, and the MCP SDK to resolve published advisories — alongside a handful of targeted fixes. Upgrading is recommended.

Also in this release:

  • Security dependencies: mongoose is bumped to 8.24.1, the plugin-mcp MCP SDK to 1.30.0 and undici is updated to pick up its latest patches
  • Dev server: Payload now connects to the correct Next.js HMR endpoint per version
  • Rich text: the link drawer preserves its form state
  • Templates: the with-cloudflare-d1 template build is fixed and its dependencies bumped


As always, you can review the complete changelog on GitHub.