Skip to content

Regarding CVE-2025-29927 in Relation to Payload CMS 3 #11835

Answered by akhrarovsaid
arinanto asked this question in Q&A
Discussion options

You must be logged in to vote

Hey @arinanto

As far as I'm aware, Payload doesn't actually utilize any middleware at all. The impact of this CVE is probably irrelevant from Payloads perspective. The only risk here is if the developer utilizes middleware in their own applications on top of Payload. That being said, version 3.30.0 was just released which bumps the Next.js peer dep to 15.2.3. Take a look at the note in that release about the impact to Payload.

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@AlessioGr
Comment options

Answer selected by arinanto
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants