GHSA-qf28-8hc6-vwrp

Suggest an improvement
Source
https://github.com/advisories/GHSA-qf28-8hc6-vwrp
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-qf28-8hc6-vwrp/GHSA-qf28-8hc6-vwrp.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-qf28-8hc6-vwrp
Aliases
  • CVE-2026-105844
Published
2026-10-06T16:09:23Z
Modified
2026-10-06T16:15:04Z
Severity
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Payload: Prototype pollution in Payload Import Export plugin
Details

Impact

An unauthenticated user could cause unintended application behavior when the Import Export plugin is enabled, allowing an attacker to submit and execute remote code (RCE).

Applications that do not use @payloadcms/plugin-import-export are not affected.

Patches

Users should upgrade Payload packages to >= 3.88.0 or >= 4.0.0-canary.27.

Workarounds

Upgrading is recommended. Until then, disable the Import Export plugin or restrict access to its endpoints.

Database specific
{
    "cwe_ids":  [
        "CWE-1321"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-10-06T16:09:23Z",
    "nvd_published_at":  null,
    "severity":  "CRITICAL"
}
References

Affected packages

npm / @payloadcms/plugin-import-export

Package

Name
@payloadcms/plugin-import-export
View open source insights on deps.dev
Purl
pkg:npm/%40payloadcms/plugin-import-export

Affected ranges

Type
SEMVER
Events
Introduced
3.0.0
Fixed
3.88.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-qf28-8hc6-vwrp/GHSA-qf28-8hc6-vwrp.json"

npm / @payloadcms/plugin-import-export

Package

Name
@payloadcms/plugin-import-export
View open source insights on deps.dev
Purl
pkg:npm/%40payloadcms/plugin-import-export

Affected ranges

Type
SEMVER
Events
Introduced
4.0.0-canary.0
Fixed
4.0.0-canary.27

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-qf28-8hc6-vwrp/GHSA-qf28-8hc6-vwrp.json"