SVG Upload Vulnerability in Payload CMS Affects Multiple Versions
CVE-2026-105862

8.7HIGH

Key Information:

Vendor

Payloadcms

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-105862?

A vulnerability in Payload CMS allows for the upload of malicious SVG files that can evade sanitization mechanisms. When users download and open these SVG files, they risk executing arbitrary JavaScript controlled by the attacker. This dangerous flaw affects all versions prior to 3.90.0 and canary versions preceding 4.0.0-canary.34. Mitigation has been implemented in the latest releases, emphasizing the need for users to update to safeguard their environments against potential exploitations.

Affected Version(s)

payload < 3.90.0 < 3.90.0

payload >= 4.0.0-canary.0, < 4.0.0-canary.34 < 4.0.0-canary.0, 4.0.0-canary.34

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.