Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-105844: Payload import-export plugin allows unauthenticated code execution
CVE-2026-105844 · published 3 days ago
Summary
The free Payload content system, when the import‑export add‑on is turned on, lets anyone without a login send specially crafted data that can make the server run their own code. This affects versions before 3.88.0 and certain early 4.0.0‑canary builds. Upgrade the product to version 3.88.0 or later (or the 4.0.0‑canary.27 release) to close the gap.
What to do
- Update payloadcms plugin-import-export to version 3.88.0.
- Update payloadcms plugin-import-export to version 4.0.0-canary.27.
- Update payloadcms @payloadcms/plugin-import-export to version 3.88.0.
- Update payloadcms @payloadcms/plugin-import-export to version 4.0.0-canary.27.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | payloadcms | payload | >= 3.0.0, < 3.88.0 |
| – | @payloadcms | plugin-import-export | >= 3.0.0, < 3.88.0 |
| npm | payloadcms | plugin-import-export |
>= 3.0.0, < 3.88.0 >= 4.0.0-canary.0, < 4.0.0-canary.27 Fix: upgrade to 3.88.0
|
| npm | payloadcms | @payloadcms/plugin-import-export |
>= 3.0.0, < 3.88.0 >= 4.0.0-canary.0, < 4.0.0-canary.27 Fix: upgrade to 3.88.0
|
Original advisory text
Payload: Prototype pollution in Payload Import Export plugin
Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.88.0 and canary versions before 4.0.0-canary.27, an unauthenticated user can submit prototype-sensitive field paths when @payloadcms/plugin-import-export is enabled, causing unintended application behavior that can lead to remote code execution. This issue is fixed in versions 3.88.0 and 4.0.0-canary.27.
References
- https://github.com/payloadcms/payload/security/advisories/GHSA-qf28-8hc6-vwrp
- https://github.com/payloadcms/payload/commit/a742140ab4fca3160f7f83e9e7d996552ff...
- https://github.com/payloadcms/payload/releases/tag/v3.88.0
- https://github.com/advisories/GHSA-qf28-8hc6-vwrp
- https://github.com/payloadcms/payload Product
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-1058... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-105844 Vendor Advisory
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-1321Prototype Pollution
Timeline
Published6 Oct 2026
Updated9 Oct 2026
First seen6 Oct 2026
Sources
CVE-2026-105844 · NVD
CVE-2026-105844 · MITRE
GHSA-qf28-8hc6-vwrp · GHSA
GHSA-qf28-8hc6-vwrp · OSV
CVE-2026-105844 · OSV
Track software like this
Free during beta