Sceawere

Vulnerability Detail

CVE-2026-105862UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Payload SVG Cross-Site Scripting

Vulnerability Metadata

Severity
High
Score / CVSS
8.7
Creation Date
8h ago
Vendor
payloadcms
Product
payload
Attack Type
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, a collection that allows downloadable SVG uploads can store a malicious SVG that bypasses sanitization and executes attacker-controlled JavaScript when a user downloads and opens the SVG. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.7",
  "pubDate": "2026-10-06T17:17:22.423Z",
  "pubdate": "2026-10-06T17:17:22.423Z",
  "executiveSummary": "Payload, a headless content management system, is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability originating from insecure SVG file uploads.\nThe vulnerability allows an attacker to bypass existing sanitization mechanisms, enabling the storage of malicious SVG files containing embedded JavaScript. When an authorized user or victim downloads and interacts with the compromised file, the embedded script executes within their browser context.\nThis flaw impacts Payload versions prior to 3.90.0 and canary versions prior to 4.0.0-canary.34.\nThe risk implication is significant, as successful exploitation permits unauthorized script execution in the context of the user's session, potentially leading to session hijacking, sensitive data exfiltration, or unauthorized administrative actions.\nThe attack requires the ability to upload files to a collection configured to accept SVG uploads. No specific complex infrastructure is required beyond the application's native upload functionality, making the attack vector straightforward for an authenticated or unauthorized user, depending on collection access controls.",
  "technicalDetails": "The vulnerability resides within the file upload handling logic of the Payload CMS, specifically concerning the processing of SVG (Scalable Vector Graphics) image files. SVG files are XML-based documents that inherently support the inclusion of scripts via elements such as <script> or event handlers (e.g., onload).\nIn the affected versions, the sanitization process intended to strip executable code from uploaded SVG files is insufficient or improperly implemented, allowing malicious payloads to bypass validation. When an attacker uploads a specially crafted SVG containing JavaScript, the application stores this file in its media library.\nThe attack flow begins with the attacker identifying a collection within Payload that permits SVG uploads. The attacker then crafts an SVG image that includes malicious JavaScript instructions. Upon submission of the file, the application fails to adequately sanitize the XML content, writing the malicious payload to the storage layer.\nWhen a victim, such as a site administrator, interacts with the compromised file—typically by viewing or downloading it through the Payload Admin UI—the browser interprets the XML structure. Because the script is not neutralized, the malicious JavaScript executes within the security context of the origin where the SVG is hosted or rendered.\nThis behavior constitutes a Stored XSS vulnerability. The impact is significant as the execution of JavaScript in the victim's browser can be leveraged to steal session cookies, perform actions on behalf of the user within the CMS, or modify content. The vulnerability affects all deployments using standard SVG upload configurations in Payload versions before 3.90.0 and 4.0.0-canary.34. The lack of robust Content Security Policy (CSP) headers or proper image transformation pipelines that re-render or sanitize SVG structures allows this bypass to remain effective."
}
CVE-2026-105862: Payload SVG Cross-Site Scripting (HIGH Severity, CVSS: 8.7) | Sceawere