PT-2026-106776 · Pyload · @Payloadcms/Plugin-Import-Export+1
CVE-2026-105844
·
Published
2026-10-06
·
Updated
2026-10-07
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Payload versions 3.0.0 through 3.87.9
Payload versions 4.0.0-canary.0 through 4.0.0-canary.26
Description
An unauthenticated user can cause unintended application behavior when the
@payloadcms/plugin-import-export plugin is enabled. By submitting prototype-sensitive field paths, an attacker can achieve remote code execution (RCE), which is the ability to execute arbitrary commands on the host machine.Recommendations
Update Payload versions 3.0.0 through 3.87.9 to version 3.88.0 or newer.
Update Payload versions 4.0.0-canary.0 through 4.0.0-canary.26 to version 4.0.0-canary.27 or newer.
Disable the
@payloadcms/plugin-import-export plugin or restrict access to its endpoints as a temporary mitigation.Exploit
Fix
RCE
Prototype Pollution
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Payloadcms/Plugin-Import-Export
Pyload