Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-105857: Payload Form Builder can run code on server

CVE-2026-105857 · published 3 days ago
Summary

The form‑building add‑on for the free Payload content system (versions before 3.90.0 and early canary builds) lets a malicious user submit specially crafted data that causes the server to execute their own code. This could let an attacker take control of the website. Upgrade to version 3.90.0 or the latest canary release to close the issue.

What to do
  • Update payloadcms plugin-form-builder to version 3.90.0.
  • Update payloadcms plugin-form-builder to version 4.0.0-canary.34.
  • Update payloadcms @payloadcms/plugin-form-builder to version 3.90.0.
  • Update payloadcms @payloadcms/plugin-form-builder to version 4.0.0-canary.34.
Affected software
Ecosystem VendorProductAffected versions
– payloadcms payload < 3.90.0
npm payloadcms plugin-form-builder < 3.90.0
>= 4.0.0-canary.0, < 4.0.0-canary.34
Fix: upgrade to 3.90.0
npm payloadcms @payloadcms/plugin-form-builder < 3.90.0
>= 4.0.0-canary.0, < 4.0.0-canary.34
Fix: upgrade to 3.90.0
Original advisory text
Payload Form Builder has an RCE issue
Payload is a free and open source headless content management system. In @payloadcms/plugin-form-builder versions before 3.90.0 and canary versions before 4.0.0-canary.34, an attacker can craft a form submission that executes code remotely on the server. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
10.0 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-94Code Injection
CWE-1321Prototype Pollution
Timeline
Published6 Oct 2026
Updated9 Oct 2026
First seen6 Oct 2026
Track software like this
Free during beta