← Blog · · df00tech

Payload CMS Import Export Plugin: Unauthenticated Prototype Pollution Leading to RCE (CVE-2026-105844)

breaking ghsa npm CVE-2026-105844

What happened

A GitHub Security Advisory (GHSA-qf28-8hc6-vwrp), tracked as CVE-2026-105844, discloses a prototype pollution vulnerability in @payloadcms/plugin-import-export, a plugin for the Payload CMS. According to the advisory, an unauthenticated user can trigger unintended application behavior through this flaw, which the vendor states can be leveraged to submit and execute remote code (RCE). A public proof-of-concept is noted as available. Payload applications that do not have the Import Export plugin installed are not affected.

Why it matters for defenders

Unauthenticated RCE in a widely-used CMS plugin is a high-severity combination: no credentials are required, and successful exploitation could grant an attacker code execution on the hosting application server. Any organization running Payload CMS with the Import Export plugin enabled — commonly used for bulk data import/export in admin panels — should treat this as exposed attack surface, particularly on internet-facing deployments. No CVSS score has been published yet, but the vendor's own framing (unauthenticated + RCE) suggests critical severity.

What defenders should watch for or do now

  • Inventory exposure: Identify any Payload CMS deployments and confirm whether @payloadcms/plugin-import-export is installed and enabled.
  • Patch or mitigate: The vendor recommends upgrading Payload to >= 3.88.0 or >= 4.0.0-canary.27. If immediate upgrade isn't feasible, disable the Import Export plugin or restrict network/access-control to its endpoints as an interim workaround.
  • Hunt for exploitation signs: Review web server and application logs for anomalous requests to import/export plugin endpoints, especially payloads attempting to manipulate object prototypes (e.g., keys like __proto__, constructor, or prototype in request bodies).
  • Monitor for follow-on activity: Since the outcome is described as RCE, watch for unexpected child processes spawned by the Node.js application, outbound connections from the app server, or new/modified files consistent with webshell deployment.

Developing intel

This is a same-day advisory with limited public detail beyond the vendor's own description; no CVSS score or confirmed in-the-wild exploitation has been reported at this time, though a public PoC reportedly exists. We will continue to track this item as more information becomes available. For full technical details, see the original advisory: GHSA-qf28-8hc6-vwrp.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.