CVE-2026-105844
Received
Received - Intake
Prototype Pollution RCE in Payload CMS
Vulnerability report for CVE-2026-105844, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-06
Last updated on: 2026-10-06
Assigner: GitHub, Inc.
Description
Description
Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.88.0 and canary versions before 4.0.0-canary.27, an unauthenticated user can submit prototype-sensitive field paths when @payloadcms/plugin-import-export is enabled, causing unintended application behavior that can lead to remote code execution. This issue is fixed in versions 3.88.0 and 4.0.0-canary.27.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| payloadcms | payload | >= 3.0.0, < 3.88.0 |
| payloadcms | payload | >= 4.0.0-canary.0, < 4.0.0-canary.27 |
| @payloadcms | plugin-import-export | >= 3.0.0, < 3.88.0 |
| @payloadcms | plugin-import-export | >= 4.0.0-canary.0, < 4.0.0-canary.27 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1321 | The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype. |