Horizon Alert
Summary of the vulnerability and why it matters
A critical security vulnerability has been identified in the @delmaredigital/payload-puck plugin, which affects how data is managed within PayloadCMS. This issue could allow unauthorized access and modification of information by bypassing established security controls. The primary concern is to confirm if this plugin is in use and if so, to understand the scope of potential exposure.
- Plugin bypasses data access controls.
- Affects data security and integrity.
- Confirm relevance and assess potential exposure.
Attack Path
How an attacker could exploit the issue
An attacker could target an internet-facing web application using the @delmaredigital/payload-puck plugin. If the plugin is configured to use default settings, attackers can send requests to specific API endpoints to bypass access controls. This allows them to perform Create, Read, Update, and Delete operations on data, potentially leading to a complete compromise of the application's data.
- No authentication required for access.
- Triggered by API requests to /api/puck/*.
- Risk of unauthorized data modification.
Live Threat
Current exploitation, exposure, and threat context
When supported by the advisory, this vulnerability could allow unauthorized access to perform Create, Read, Update, and Delete (CRUD) operations on system data. This could occur through exposed API endpoints when the plugin's access controls are bypassed.
- Unauthorized data modification or deletion.
- Via exposed API endpoints.
- Potential compromise of system integrity.
Operational Fix
Recommended remediation, mitigation, and detection steps
Application owners responsible for PayloadCMS instances and the platform or infrastructure teams supporting them should lead the remediation efforts. The immediate first step is to identify all instances of the affected plugin, confirm their exposure to the network and business criticality, and then assign ownership for the remediation plan.
- Application owners must own this issue.
- Verify API endpoint exposure and business criticality.
- Plan remediation and coordinate vendor updates.