Payload CMS, Unrestricted File Upload and Same-Origin JavaScript Execution, CVE-2026-105868 (High) -DC-Oct2026-2858

Listen to this Post

CVE-2026-105868 is a high-severity security vulnerability affecting Payload CMS local upload configurations. The core issue arises when an application permits the uploading and serving of XML files alongside XSL stylesheets. In vulnerable versions, an authenticated or unauthenticated threat actor capable of uploading files can supply a specially crafted XML file coupled with a stylesheet containing embedded JavaScript code. When a targeted logged-in user or administrator accesses or opens this uploaded file directly within the application’s domain context, the browser interprets the XML and stylesheet combination, causing the embedded script to execute within the application’s same-origin context. This allows malicious code to interact with session cookies, perform unauthorized actions on behalf of the victim, or access sensitive application data stored under the same origin. Remediation requires upgrading the framework to version 3.90.0 or 4.0.0-canary.34, or completely disabling XML and XSL file uploads as an immediate workaround.

DailyCVE Form:

Platform: Payload CMS
Version: < 3.90.0
Vulnerability : XML/XSL Upload XSS
Severity: High
date: October 6, 2026

Prediction: October 6, 2026

What Undercode Say:

This vulnerability highlights the dangers of allowing unrestricted local file uploads, particularly file types like XML that support embedded stylesheets capable of executing active content in modern web browsers. Developers must strictly enforce content type validation and restrict dangerous file extensions from being processed and served directly by the application origin.

Analytics:

Check installed payload version
npm list payload
Update payload to the patched version
npm install [email protected]

Exploit: (Educational Purposes!)

An attacker prepares a malicious XML file referencing an XSL stylesheet containing script tags or event handlers:

<?xml-stylesheet type="text/xsl" href="stylesheet"?>
<xsl:stylesheet id="stylesheet" version="1.0" xmlns:xsl="http://www.w3.org/1999/XSLT">
<xsl:template match="/">
<html>
<script>alert(document.domain);</script>
</html>
</xsl:template>
</xsl:stylesheet>

When uploaded and opened by a user in the same origin, the script executes.

Protection: from this CVE

Upgrade Payload packages to version 3.90.0 or 4.0.0-canary.34 immediately. If upgrading is not immediately feasible, configure upload filters to disallow XML and XSL file uploads entirely.

Impact:

Successful exploitation allows malicious scripts to execute within the Payload application origin when opened by an authenticated user, potentially leading to session hijacking, credential exposure, or unauthorized actions performed within the application context.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top