SVG Upload Vulnerability in Payload CMS Affects Multiple Versions
CVE-2026-105862
8.7HIGH
What is CVE-2026-105862?
A vulnerability in Payload CMS allows for the upload of malicious SVG files that can evade sanitization mechanisms. When users download and open these SVG files, they risk executing arbitrary JavaScript controlled by the attacker. This dangerous flaw affects all versions prior to 3.90.0 and canary versions preceding 4.0.0-canary.34. Mitigation has been implemented in the latest releases, emphasizing the need for users to update to safeguard their environments against potential exploitations.
Affected Version(s)
payload < 3.90.0 < 3.90.0
payload >= 4.0.0-canary.0, < 4.0.0-canary.34 < 4.0.0-canary.0, 4.0.0-canary.34
