Missing Authorization@payloadcms/storage-vercel-blob is a Payload storage adapter for Vercel Blob Storage
Affected versions of this package are vulnerable to Missing Authorization in the getClientUploadRoute handler for the client-upload path. An attacker can upload files by sending a client upload request to the Vercel Storage adapter’s signed-upload endpoint without satisfying the target collection’s access rules. In affected configurations, authenticated users with access to the route can bypass collection-level create or update checks and obtain upload access even when the collection should deny it. This lets the attacker write files through the upload flow, bypassing the intended per-collection upload restrictions for that storage-backed field.
Workarounds
- Disable client uploads for
@payloadcms/storage-vercel-blob until you can upgrade; this prevents attackers from reaching the signed client-upload endpoint and bypassing collection-level upload restrictions.
- If you must keep client uploads enabled, configure the upload route’s access control so it enforces the associated collection’s
create/update permissions; this blocks unauthorized users from obtaining upload access through the client-upload path.
How to fix Missing Authorization? Upgrade @payloadcms/storage-vercel-blob to version 3.90.0, 4.0.0-canary.34 or higher.
| >=3.25.0 <3.90.0>=4.0.0-canary.0 <4.0.0-canary.34 |