CVE-2026-105868
Received Received - Intake

Stored XSS in Payload CMS via XML Upload

Vulnerability report for CVE-2026-105868, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: GitHub, Inc.

Description

Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, local upload configurations that accept XML files can store an XML file and stylesheet that execute JavaScript in the Payload origin when a logged-in user opens the file. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
payloadcms payload < 3.90.0
payloadcms payload >= 4.0.0-canary.0, < 4.0.0-canary.34

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Payload CMS versions before 3.90.0 and canary versions before 4.0.0-canary.34 have a vulnerability where local upload configurations accepting XML files can store malicious XML and stylesheets. When a logged-in user opens the file, JavaScript executes in the Payload origin.

Detection Guidance

Detect this vulnerability by checking Payload CMS versions before 3.90.0 or canary versions before 4.0.0-canary.34. Inspect uploaded XML files for suspicious JavaScript execution in stylesheets. Review server logs for unexpected file uploads or access patterns.

Impact Analysis

An attacker could upload a malicious XML file and stylesheet to exploit this vulnerability. If a logged-in user accesses the file, the attacker could execute arbitrary JavaScript in the context of the Payload CMS application, potentially leading to data theft, session hijacking, or other malicious actions.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements under GDPR and HIPAA. Organizations using affected versions may face compliance violations, data breaches, and potential legal consequences.

Mitigation Strategies

Upgrade Payload CMS to version 3.90.0 or 4.0.0-canary.34 or later. Remove or restrict local upload configurations that accept XML files. Implement strict file upload validation to block XML files with embedded scripts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105868. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart