Sceawere
Vulnerability Detail
CVE-2026-105857UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Payload Form Builder RCE
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 10
- Creation Date
- 8h ago
- Vendor
- payloadcms
- Product
- payload
- Attack Type
- CWE-94: Improper Control of Generation of Code ('Code Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Payload is a free and open source headless content management system. In @payloadcms/plugin-form-builder versions before 3.90.0 and canary versions before 4.0.0-canary.34, an attacker can craft a form submission that executes code remotely on the server. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "10.0",
"pubDate": "2026-10-06T17:17:21.710Z",
"pubdate": "2026-10-06T17:17:21.710Z",
"executiveSummary": "The @payloadcms/plugin-form-builder package is susceptible to a Remote Code Execution (RCE) vulnerability. This security flaw allows a remote, unauthenticated attacker to execute arbitrary system commands on the hosting server by submitting a specifically crafted form payload.\nThe vulnerability originates from improper handling of form submission data, which enables the injection of malicious code into the server environment. Successful exploitation results in complete system compromise, potentially allowing an attacker to access sensitive data, modify application files, or establish persistence within the infrastructure.\nThis vulnerability affects versions of @payloadcms/plugin-form-builder prior to 3.90.0 and versions prior to 4.0.0-canary.34. Due to the high severity of Remote Code Execution vulnerabilities, immediate patching is required to mitigate the risk of unauthorized server-side command execution.",
"technicalDetails": "The vulnerability resides within the @payloadcms/plugin-form-builder component, specifically in how the plugin processes and handles form submission input. The root cause of this RCE vulnerability is the insecure deserialization or improper sanitization of input data provided through form fields during the submission process.\nWhen a user submits a form, the plugin processes the provided fields to store or handle the data. In the vulnerable versions, the input data is not sufficiently validated or neutralized before being passed to an execution sink. By crafting a malicious form submission payload, an attacker can bypass existing validation layers to inject arbitrary code or commands that the server-side environment subsequently interprets and executes.\nThe attack flow begins with the discovery of the form endpoint, which is exposed to the network to allow user submissions. An attacker does not require prior authentication to interact with these forms. The attacker constructs a payload containing malicious system commands or code instructions embedded within a legitimate form field structure. Upon submission, the plugin fails to properly isolate this input, allowing the underlying Node.js runtime or system shell to evaluate the injected commands.\nBecause the payload is processed at the application layer, the executed commands inherit the privileges of the system process running the Payload CMS instance. This facilitates full Remote Code Execution (RCE), enabling the attacker to perform post-exploitation activities such as exfiltrating database contents, accessing environment variables containing credentials, or pivoting to other segments of the internal network.\nThe flaw affects @payloadcms/plugin-form-builder versions before 3.90.0 and canary versions before 4.0.0-canary.34. The lack of strict input typing and the existence of dangerous sink functions during the submission handling pipeline constitute the primary vectors for this exploit. Systems exposed to the public internet are at significant risk, as the exploitation requirement is limited to the ability to submit form data to the application's API endpoints."
}