Listen to this Post
CVE-2026-105868 is a high-severity security vulnerability affecting Payload CMS local upload configurations. The core issue arises when an application permits the uploading and serving of XML files alongside XSL stylesheets. In vulnerable versions, an authenticated or unauthenticated threat actor capable of uploading files can supply a specially crafted XML file coupled with a stylesheet containing embedded JavaScript code. When a targeted logged-in user or administrator accesses or opens this uploaded file directly within the application’s domain context, the browser interprets the XML and stylesheet combination, causing the embedded script to execute within the application’s same-origin context. This allows malicious code to interact with session cookies, perform unauthorized actions on behalf of the victim, or access sensitive application data stored under the same origin. Remediation requires upgrading the framework to version 3.90.0 or 4.0.0-canary.34, or completely disabling XML and XSL file uploads as an immediate workaround.
DailyCVE Form:
Platform: Payload CMS
Version: < 3.90.0
Vulnerability : XML/XSL Upload XSS
Severity: High
date: October 6, 2026
Prediction: October 6, 2026
What Undercode Say:
This vulnerability highlights the dangers of allowing unrestricted local file uploads, particularly file types like XML that support embedded stylesheets capable of executing active content in modern web browsers. Developers must strictly enforce content type validation and restrict dangerous file extensions from being processed and served directly by the application origin.
Analytics:
Check installed payload version npm list payload Update payload to the patched version npm install [email protected]
Exploit: (Educational Purposes!)
An attacker prepares a malicious XML file referencing an XSL stylesheet containing script tags or event handlers:
<?xml-stylesheet type="text/xsl" href="stylesheet"?> <xsl:stylesheet id="stylesheet" version="1.0" xmlns:xsl="http://www.w3.org/1999/XSLT"> <xsl:template match="/"> <html> <script>alert(document.domain);</script> </html> </xsl:template> </xsl:stylesheet>
When uploaded and opened by a user in the same origin, the script executes.
Protection: from this CVE
Upgrade Payload packages to version 3.90.0 or 4.0.0-canary.34 immediately. If upgrading is not immediately feasible, configure upload filters to disallow XML and XSL file uploads entirely.
Impact:
Successful exploitation allows malicious scripts to execute within the Payload application origin when opened by an authenticated user, potentially leading to session hijacking, credential exposure, or unauthorized actions performed within the application context.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

