An unauthenticated user could cause unintended application behavior when the Import Export plugin is enabled, allowing an attacker to submit and execute remote code (RCE).
Applications that do not use @payloadcms/plugin-import-export are not affected.
// patches
Users should upgrade Payload packages to >= 3.88.0 or >= 4.0.0-canary.27.
// workarounds
Upgrading is recommended. Until then, disable the Import Export plugin or restrict access to its endpoints.