CVE-2026-105848: Payload: Insufficient Access Control in Stripe REST Proxy
An authenticated user could perform unintended Stripe operations through the optional Stripe REST proxy.
You are affected if ALL of these are true:
- Your application uses
@payloadcms/plugin-stripe. - The optional Stripe REST proxy is enabled.
- An authenticated user can reach the proxy.
Deployments that do not enable the Stripe REST proxy are not affected.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-105848 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →