← Blog · · df00tech

Critical RCE in Payload CMS Form Builder Plugin (CVE-2026-105857, CVSS 10.0)

breaking ghsa npm CVE-2026-105857

What happened

A GitHub Security Advisory (GHSA-r488-j9vj-wx3q) discloses a remote code execution vulnerability in @payloadcms/plugin-form-builder versions prior to 3.90.0, tracked as CVE-2026-105857 with a maximum CVSS score of 10.0. According to the advisory, crafted form submissions could be used to execute arbitrary code on the server. A proof-of-concept is reported as publicly available. The advisory states the fix is in versions >= 3.90.0 or >= 4.0.0-canary.34.

Why it matters

Payload is a popular open-source headless CMS, and the form-builder plugin is a common add-on for handling public-facing form submissions — meaning the vulnerable code path is often exposed directly to unauthenticated users. A maximum-severity RCE reachable via ordinary form submission, combined with public PoC availability, makes this an attractive target for opportunistic scanning and automated exploitation. Any site or application using this plugin below the patched version should be considered at risk.

What defenders should do now

  • Inventory all Node.js/Payload CMS deployments and check whether @payloadcms/plugin-form-builder is installed and at what version.
  • Prioritize upgrading to >= 3.90.0 (or >= 4.0.0-canary.34) immediately given the CVSS 10.0 rating and public PoC.
  • Until patched, consider disabling or restricting access to form-builder submission endpoints, and review WAF/reverse-proxy rules for anomalous payloads in form submission requests.
  • Hunt for unexpected child processes spawned by the Node.js process hosting Payload, unusual outbound connections, or new/modified files on disk around the time of form submissions — classic indicators of a web-app RCE being exercised.
  • Review recent form-submission logs for malformed or unusually structured payloads targeting form-builder endpoints.

Developing intel

This is net-new intelligence based solely on the GitHub Security Advisory; exploitation in the wild has not been confirmed in the source material, and full technical root-cause details were not included in the advisory excerpt reviewed here. We will continue to track this item. For the authoritative details and patch guidance, see the original advisory: GHSA-r488-j9vj-wx3q.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.