Under certain conditions, an authenticated user could manage MCP API keys outside their intended account allowing an attacker to escalate privileges through account takeover.
Applications that do not use @payloadcms/plugin-mcp are not affected.
// patches
Users should upgrade to @payloadcms/plugin-mcp version 3.88.0 or later.
// workarounds
Upgrading is recommended. Until then, disable the MCP plugin or restrict MCP API-key management to trusted users.