Payload Server-Side Request Forgery Vulnerability in External File Uploads

Vulnerability

A Server-Side Request Forgery (SSRF) vulnerability has been identified in Payload, a headless content management system, in versions prior to 3.75.0. This vulnerability arises in the external file upload feature, where inadequate validation of HTTP redirects allows authenticated attackers to access internal network resources. To be vulnerable, the Payload environment must have at least one collection with upload enabled, and the user must have create access to that collection. Exploitation could enable access to internal services, with the potential to retrieve response content from those services through the application.

Impact

Exploitation of this vulnerability could lead to unauthorized access to internal network resources, allowing an authenticated user to retrieve sensitive information from internal services via the application.

Reproduction

The vulnerability can be reproduced by uploading a file through an external URL to a collection that has the upload feature enabled. The uploaded URL should be crafted to include a redirect to an internal service, which can then be accessed through the application, demonstrating the SSRF vulnerability.

Remediation

Users are advised to upgrade to Payload version 3.75.0 or later. If an immediate upgrade is not possible, the vulnerability can be mitigated by disabling external file uploads on the affected collection or by restricting create access to trusted users only.

Added: Feb 24, 2026, 3:27 PM
Updated: Feb 24, 2026, 10:24 PM

Vulnerability Rating

Custom Algorithm
spread
2.2
impact
0.6
exploitability
5.8
remediation
7.9
relevance
3.1
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.