@jhb.software/payload-cloudinary-plugin
js · @jhb.software/payload-cloudinary-pluginCritical
@jhb.software/payload-cloudinary-plugin: Unrestricted signature generation via paramsToSign
The plugin's signing endpoint at POST /api/cloudinary-generate-signature passes attacker-supplied paramsToSign directly to cloudin
20 Jun 2026 · act now