DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-105844: CVE-2026-105844: Remote Code Execution via Prototype Pollution in @payloadcms/plugin-import-export

CVE-2026-105844: Remote Code Execution via Prototype Pollution in @payloadcms/plugin-import-export

Vulnerability ID: CVE-2026-105844
CVSS Score: 9.3
Published: 2026-10-06

A critical prototype pollution vulnerability in the import-export plugin of Payload CMS allows unauthenticated remote attackers to bypass access controls and achieve remote code execution.

TL;DR

Unauthenticated remote attackers can pollute the global object prototype in Payload CMS to bypass access controls and execute arbitrary code on the server.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-1321
  • Attack Vector: Network (AV:N)
  • CVSS Score: 9.3 (Critical)
  • EPSS Score: N/A
  • Impact: Remote Code Execution (RCE) / Privilege Escalation
  • Exploit Status: Proof of Concept (PoC) documented
  • KEV Status: Not listed

Affected Systems

  • Payload CMS instances running @payloadcms/plugin-import-export < 3.88.0
  • Payload CMS (@payloadcms/plugin-import-export): >= 3.0.0, < 3.88.0 (Fixed in: 3.88.0)
  • Payload CMS (canary): < 4.0.0-canary.27 (Fixed in: 4.0.0-canary.27)

Code Analysis

Commit: a742140

Fix import export prototype-sensitive field paths RCE

Exploit Details

Mitigation Strategies

  • Upgrade to Payload CMS v3.88.0 or 4.0.0-canary.27
  • Deploy Web Application Firewall (WAF) signatures to block request payloads containing proto or constructor paths
  • Restrict network access to export preview endpoints if they are not strictly required for external operations

Remediation Steps:

  1. Run 'npm install payload@3.88.0 @payloadcms/plugin-import-export@3.88.0' to upgrade the monorepo.
  2. Verify the installation using 'npm list payload @payloadcms/plugin-import-export'.
  3. Restart the node application to apply the code changes in-memory.

References


Read the full report for CVE-2026-105844 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)