@payloadcms/storage-vercel-blob@3.83.0-internal.06ac84e

Payload storage adapter for Vercel Blob Storage

  • latest version

    3.90.2

  • latest non vulnerable version

  • first published

    2 years ago

  • latest version published

    8 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the @payloadcms/storage-vercel-blob package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Missing Authorization

    @payloadcms/storage-vercel-blob is a Payload storage adapter for Vercel Blob Storage

    Affected versions of this package are vulnerable to Missing Authorization in the getClientUploadRoute handler for the client-upload path. An attacker can upload files by sending a client upload request to the Vercel Storage adapter’s signed-upload endpoint without satisfying the target collection’s access rules. In affected configurations, authenticated users with access to the route can bypass collection-level create or update checks and obtain upload access even when the collection should deny it. This lets the attacker write files through the upload flow, bypassing the intended per-collection upload restrictions for that storage-backed field.

    Workarounds

    • Disable client uploads for @payloadcms/storage-vercel-blob until you can upgrade; this prevents attackers from reaching the signed client-upload endpoint and bypassing collection-level upload restrictions.
    • If you must keep client uploads enabled, configure the upload route’s access control so it enforces the associated collection’s create/update permissions; this blocks unauthorized users from obtaining upload access through the client-upload path.

    How to fix Missing Authorization?

    Upgrade @payloadcms/storage-vercel-blob to version 3.90.0, 4.0.0-canary.34 or higher.

    >=3.25.0 <3.90.0>=4.0.0-canary.0 <4.0.0-canary.34