Payload: Prototype pollution in Payload Import Export plugin
An unauthenticated user could cause unintended application behavior when the Import Export plugin is enabled, allowing an attacker to submit and execute remote code (RCE). Applications that do not use @payloadcms/plugin-import-export are not affected.