HIGH 7.1 GitHub
CVE-2026-59965
@jhb.software/payload-alt-text-plugin: Alt Text Endpoint Authorization Bypass via Payload Local API `overrideAccess` Omission
## Alt Text Endpoint Authorization Bypass via Payload Local API `overrideAccess` Omission
### Summary
`@jhb.software/payload-alt-text-plugin` v0.7.0 exposes custom Payload CMS endpoints (`POST /api/alt-text-plugin/generate` and `/bulk`) that call the Payload Local API (`findByID` and `update`) without setting `overrideAccess: false`. Because Payload's internal logic evaluates `shouldOverrideAccess = overrideAccess !== false`, omitting the parameter causes it to default to `true`, silently bypa
Affected Products
- npm/@jhb.software/payload-alt-text-plugin <= 0.7.0
References
- https://github.com/advisories/GHSA-4qpv-39hg-f7fx
- https://github.com/jhb-software/payload-plugins/security/advisories/GHSA-4qpv-39hg-f7fx
- https://github.com/advisories/GHSA-4qpv-39hg-f7fx
This high severity vulnerability with a CVSS score of 7.1 was published on 2026-09-10 via GitHub. Affected: npm/@jhb.software/payload-alt-text-plugin <= 0.7.0.
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.