Medium severity5.4NVD Advisory· Published Apr 1, 2026· Updated Apr 13, 2026
CVE-2026-34749
CVE-2026-34749
Description
Payload is a free and open source headless content management system. Prior to version 3.79.1, a Cross-Site Request Forgery (CSRF) vulnerability exists in the authentication flow. Under certain conditions, the configured CSRF protection could be bypassed, allowing cross-site requests to be made. This issue has been patched in version 3.79.1.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
payloadnpm | < 3.79.1 | 3.79.1 |
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/advisories/GHSA-p6mr-xf3r-ghq4ghsaADVISORY
- github.com/payloadcms/payload/security/advisories/GHSA-p6mr-xf3r-ghq4nvdVendor AdvisoryMitigationWEB
- nvd.nist.gov/vuln/detail/CVE-2026-34749ghsaADVISORY
- github.com/payloadcms/payload/releases/tag/v3.79.1nvdProductRelease NotesWEB
News mentions
50- Funnel Builder Flaw Under Active Exploitation Enables WooCommerce Checkout SkimmingThe Hacker News · May 16, 2026
- Funnel Builder WordPress plugin bug exploited to steal credit cardsBleepingComputer · May 15, 2026
- Metasploit Wrap-Up 05/15/2026Rapid7 Blog · May 15, 2026
- In Other News: Big Tech vs Canada Encryption Bill, Cisco’s Free AI Security Spec, Audi App FlawsSecurityWeek · May 15, 2026
- Gremlin Stealer Evolves into Modular Threat with Advanced Evasion CapabilitiesInfosecurity Magazine · May 15, 2026
- Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource FilesUnit 42 · May 15, 2026
- China-Linked Hackers Deploy New TencShell Malware Against Global ManufacturerInfosecurity Magazine · May 15, 2026
- Stealer Backdoor Found in 3 Node-IPC Versions Targeting Developer SecretsThe Hacker News · May 14, 2026
- 'FrostyNeighbor' APT Carefully Targets Govt Orgs in Poland, UkraineDark Reading · May 14, 2026
- ThreatsDay Bulletin: PAN-OS RCE, Mythos cURL Bug, AI Tokenizer Attacks, and 10+ StoriesThe Hacker News · May 14, 2026
- Cyber-Enabled Cargo Crime: How Cybercrime Tradecraft is Used to Steal FreightBleepingComputer · May 14, 2026
- Mustang Panda Linked to Updated FDMTP Backdoor in Asia-Pacific Espionage CampaignInfosecurity Magazine · May 14, 2026
- Ghostwriter Targets Ukrainian Government With Geofenced PDF Phishing, Cobalt StrikeThe Hacker News · May 14, 2026
- New Fragnesia Flaw Hands Linux Local Users Root AccessInfosecurity Magazine · May 14, 2026
- Chinese APTs Expand Targets, Update Backdoors in Recent CampaignsSecurityWeek · May 14, 2026
- Kimsuky targets organizations with PebbleDash-based toolsSecurelist · May 14, 2026
- FrostyNeighbor: Fresh mischief and digital shenanigansESET WeLiveSecurity · May 14, 2026
- New Fragnesia Linux Kernel LPE Grants Root Access via Page Cache CorruptionThe Hacker News · May 14, 2026
- Vector embedding security gap exposes enterprise AI pipelinesHelp Net Security · May 14, 2026
- Attackers Weaponize RubyGems for Data Dead DropsDark Reading · May 13, 2026
- When IT Support Calls: Dissecting a ModeloRAT Campaign from Teams to Domain CompromiseRapid7 Blog · May 13, 2026
- China's 'FamousSparrow' APT Nests in South Caucasus Energy FirmDark Reading · May 13, 2026
- Azerbaijani Energy Firm Hit by Repeated Microsoft Exchange ExploitationThe Hacker News · May 13, 2026
- GemStuffer Abuses 150+ RubyGems to Exfiltrate Scraped U.K. Council Portal DataThe Hacker News · May 13, 2026
- Fake Claude search results lure Mac users into ClickFix attackMalwarebytes Labs · May 12, 2026
- Mini Shai-Hulud Hits TanStack npm PackagesInfosecurity Magazine · May 12, 2026
- Free OnlyFans Lure Used to Spread Cross-Platform CRPx0 MalwareSecurityWeek · May 12, 2026
- 20 Leaders Who Built the CISO Era: 2 Decades of ChangeDark Reading · May 12, 2026
- Cache-poisoning caper turns TanStack npm packages toxicThe Register Security · May 12, 2026
- Attackers Combine ClickFix With PySoxy Proxying to Maintain PersistenceInfosecurity Magazine · May 12, 2026
- Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More PackagesThe Hacker News · May 12, 2026
- Shai Hulud attack ships signed malicious TanStack, Mistral npm packagesBleepingComputer · May 12, 2026
- Is the SOC Obsolete, and We Just Haven’t Admitted It Yet?SecurityWeek · May 12, 2026
- TanStack, Mistral AI, UiPath Hit in Fresh Supply Chain AttackSecurityWeek · May 12, 2026
- State-sponsored actors, better known as the friends you don’t wantCisco Talos Intelligence · May 12, 2026
- Malicious Hugging Face Repository Typosquats OpenAIInfosecurity Magazine · May 12, 2026
- Cookie thieves caught stealing dev secrets via fake Claude Code installersThe Register Security · May 11, 2026
- Tech Can't Stop These Threats — Your People CanDark Reading · May 11, 2026
- Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass ExploitationThe Hacker News · May 11, 2026
- Google researchers uncover criminal zero-day exploit likely built with AIHelp Net Security · May 11, 2026
- ⚡ Weekly Recap: Linux Rootkit, macOS Crypto Stealer, WebSocket Skimmers and MoreThe Hacker News · May 11, 2026
- Hackers abuse Google ads, Claude.ai chats to push Mac malwareBleepingComputer · May 10, 2026
- JDownloader site hacked to replace installers with Python RAT malwareBleepingComputer · May 9, 2026
- Fake OpenAI repository on Hugging Face pushes infostealer malwareBleepingComputer · May 9, 2026
- Metasploit Wrap-Up 05/08/2026Rapid7 Blog · May 8, 2026
- TCLBANKER Banking Trojan Targets Financial Platforms via WhatsApp and Outlook WormsThe Hacker News · May 8, 2026
- Zero Chaos: Scaling Detection Engineering at the Speed of Software, with Detection As CodeRapid7 Blog · May 8, 2026
- New TCLBanker malware self-spreads over WhatsApp and OutlookBleepingComputer · May 7, 2026
- Unplug your way to better codeCisco Talos Intelligence · May 7, 2026
- PCPJack Credential Stealer Exploits 5 CVEs to Spread Worm-Like Across Cloud SystemsThe Hacker News · May 7, 2026