Sceawere
Vulnerability Detail
CVE-2026-105865UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Payload Directory Traversal File Deletion
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.1
- Creation Date
- 8h ago
- Vendor
- payloadcms
- Product
- payload
- Attack Type
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an authenticated user who can update or delete uploads stored locally can cause file cleanup to remove unintended files outside the configured upload directory, resulting in data loss or service disruption. Deployments that restrict upload management to trusted users are less exposed. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.1",
"pubDate": "2026-10-06T17:17:22.843Z",
"pubdate": "2026-10-06T17:17:22.843Z",
"executiveSummary": "A directory traversal vulnerability exists in Payload CMS, enabling an authenticated user with upload management privileges to perform unauthorized file deletions outside the intended storage directory.\nThe vulnerability is classified as an improper neutralization of special elements used in a path (path traversal).\nImpact includes potential data loss, service disruption, and system instability due to the ability to delete arbitrary files on the host filesystem.\nAffected products include Payload versions prior to 3.90.0 and canary versions before 4.0.0-canary.34.\nExploitation requires the attacker to possess authenticated access to the application with permissions to update or delete media uploads.\nWhile the attack surface is limited to authenticated users, the risk is significant for multi-tenant environments or systems where administrative roles are delegated to less-trusted users.",
"technicalDetails": "The vulnerability resides in the file handling logic responsible for the cleanup of uploads stored locally. It stems from insufficient validation and sanitization of file paths during the deletion or update process.\nAn authenticated user with sufficient privileges to modify or remove uploads can manipulate the path parameters associated with media objects. By injecting directory traversal sequences (e.g., ../) into the file path, the user can escape the restricted upload directory configured within the CMS.\nThe attack flow initiates when the malicious actor submits an API request to update or delete a media resource. The backend application, failing to resolve or constrain the target path within the designated sandbox, executes a file system operation targeting the resolved malicious path.\nBecause the cleanup function operates with the privileges of the Node.js process running the Payload instance, the application can delete any file that the process has write or execute permissions to access on the underlying operating system.\nThis behavior facilitates a path traversal attack that circumvents the intended security boundary of the uploads directory. If the application is running with elevated privileges or if the process owner has access to sensitive configuration files, system binaries, or application code, an attacker could potentially delete critical system files, causing a denial-of-service (DoS) state or complete system compromise through the removal of necessary runtime dependencies.\nThe vulnerability is present in versions of Payload prior to 3.90.0 and 4.0.0-canary.34. The flaw highlights a failure in path canonicalization and enforcement, where the input path provided by the user is not validated against the expected root directory before invoking the deletion syscall."
}