# Payload v3.87.1 - Product: Payload (https://whatsnew.fyi/product/payload-cms) - Vendor: Payload - Date: 2026-08-06 - Version: v3.87.1 - Original notes: https://github.com/payloadcms/payload/releases/tag/v3.87.1 - Permalink: https://whatsnew.fyi/product/payload-cms/releases/v3.87.1 What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- - **fixed** — Connect to the correct Next.js dev HMR endpoint per version - **security** — Bump mongoose to 8.24.1 for GHSA-664h-wqgq-64gw - **security** — Bump undici for security vulnerability - **security** — Bump @modelcontextprotocol/sdk to 1.30.0 for GHSA-frvp-7c67-39w9 - **fixed** — Preserve link drawer form state in richtext-lexical - **fixed** — Fix with-cloudflare-d1 build and bump dependencies ##### [v3.87.1](https://github.com/payloadcms/payload/compare/v3.87.0...v3.87.1) (2026-08-06) ###### 🐛 Bug Fixes * connect to the correct Next.js dev HMR endpoint per version ([#17644](https://github.com/payloadcms/payload/issues/17644)) ([291ac66](https://github.com/payloadcms/payload/commit/291ac66)) * **db-mongodb:** bump mongoose to 8.24.1 for GHSA-664h-wqgq-64gw (3.x backport of #17609) ([#17608](https://github.com/payloadcms/payload/issues/17608)) ([f039324](https://github.com/payloadcms/payload/commit/f039324)) * **deps:** bump undici ([#17630](https://github.com/payloadcms/payload/issues/17630)) ([9e2c11e](https://github.com/payloadcms/payload/commit/9e2c11e)) * **plugin-mcp:** bump @modelcontextprotocol/sdk to 1.30.0 for GHSA-frvp-7c67-39w9 (3.x) ([#17611](https://github.com/payloadcms/payload/issues/17611)) ([0cb605d](https://github.com/payloadcms/payload/commit/0cb605d)) * **richtext-lexical:** preserve link drawer form state ([#17586](https://github.com/payloadcms/payload/issues/17586)) ([90fb9e1](https://github.com/payloadcms/payload/commit/90fb9e1)) * **templates:** fix with-cloudflare-d1 build and bump dependencies ([#17577](https://github.com/payloadcms/payload/issues/17577)) ([ca3e899](https://github.com/payloadcms/payload/commit/ca3e899)) ###### 📚 Documentation * update admin panel location link in custom components docs ([#17624](https://github.com/payloadcms/payload/issues/17624)) ([57178e3](https://github.com/payloadcms/payload/commit/57178e3)) ###### ⚙️ CI * allow changes job to check out repository ([#17643](https://github.com/payloadcms/payload/issues/17643)) ([ec4f979](https://github.com/payloadcms/payload/commit/ec4f979)) ###### 🤝 Contributors - Nate Lentz (@nathanlentz) - Jarrod Flesch (@JarrodMFlesch) - Elliot DeNolf (@denolfe) - Sean Zubrickas (@zubricks) - Patrik (@PatrikKozak)