Payload: Token refresh and password reset responses may expose restricted user fields
Package
Affected versions
>= 3.0.0, < 3.90.0
>= 4.0.0-canary.0, < 4.0.0-canary.34
Patched versions
3.90.0
4.0.0-canary.34
Description
Published to the GitHub Advisory Database
Oct 6, 2026
Reviewed
Oct 6, 2026
Last updated
Oct 6, 2026
Impact
Token refresh and password reset responses could return fields that the requesting user did not have access to.
You are affected if:
Patches
Authentication responses now apply field access and hidden-field filtering before returning user documents. Full user documents remain available server-side for access control.
Users should upgrade Payload packages to
>= 3.90.0or>= 4.0.0-canary.34.Custom authentication strategies remain responsible for filtering user documents returned through custom responses.
Workarounds
There is no complete workaround. Users should upgrade Payload packages to
>= 3.90.0or>= 4.0.0-canary.34.References