IA Squad
SearchPT

@jhb.software/payload-cloudinary-plugin

js · @jhb.software/payload-cloudinary-pluginCritical

@jhb.software/payload-cloudinary-plugin: Unrestricted signature generation via paramsToSign

The plugin's signing endpoint at POST /api/cloudinary-generate-signature passes attacker-supplied paramsToSign directly to cloudin

20 Jun 2026 · act now