CVE-2026-105844: Payload: Prototype pollution in Payload Import Export plugin
### Impact An unauthenticated user could cause unintended application behavior when the Import Export plugin is enabled, allowing an attacker to submit and execute remote code (RCE). Applications that do not use `@payloadcms/plugin-import-export` are not affected. ### Patches Users should upgrade Payload packages to `>= 3.88.0` or `>= 4.0.0-canary.27.` ### Workarounds Upgrading is recommended. Until then, disable the Import Export plugin or restrict access to its endpoints.
Recommended action
Recommended action
Upgrade affected packages to a patched version: @payloadcms/plugin-import-export 3.88.0, @payloadcms/plugin-import-export 4.0.0-canary.27.
Technical details
- Vendor
- Not specified
- Product
- @payloadcms/plugin-import-export
- Exploitation
- none known
- Evidence
- official
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source