CVE-2026-105844: Remote Code Execution via Prototype Pollution in @payloadcms/plugin-import-export
Vulnerability ID: CVE-2026-105844
CVSS Score: 9.3
Published: 2026-10-06
A critical prototype pollution vulnerability in the import-export plugin of Payload CMS allows unauthenticated remote attackers to bypass access controls and achieve remote code execution.
TL;DR
Unauthenticated remote attackers can pollute the global object prototype in Payload CMS to bypass access controls and execute arbitrary code on the server.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-1321
- Attack Vector: Network (AV:N)
- CVSS Score: 9.3 (Critical)
- EPSS Score: N/A
- Impact: Remote Code Execution (RCE) / Privilege Escalation
- Exploit Status: Proof of Concept (PoC) documented
- KEV Status: Not listed
Affected Systems
- Payload CMS instances running @payloadcms/plugin-import-export < 3.88.0
-
Payload CMS (@payloadcms/plugin-import-export): >= 3.0.0, < 3.88.0 (Fixed in:
3.88.0) -
Payload CMS (canary): < 4.0.0-canary.27 (Fixed in:
4.0.0-canary.27)
Code Analysis
Commit: a742140
Fix import export prototype-sensitive field paths RCE
Exploit Details
- GitHub Security Advisory: Proof of concept and root-cause analysis
Mitigation Strategies
- Upgrade to Payload CMS v3.88.0 or 4.0.0-canary.27
- Deploy Web Application Firewall (WAF) signatures to block request payloads containing proto or constructor paths
- Restrict network access to export preview endpoints if they are not strictly required for external operations
Remediation Steps:
- Run 'npm install payload@3.88.0 @payloadcms/plugin-import-export@3.88.0' to upgrade the monorepo.
- Verify the installation using 'npm list payload @payloadcms/plugin-import-export'.
- Restart the node application to apply the code changes in-memory.
References
Read the full report for CVE-2026-105844 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)