CVE-2026-105865

high

Description

Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an authenticated user who can update or delete uploads stored locally can cause file cleanup to remove unintended files outside the configured upload directory, resulting in data loss or service disruption. Deployments that restrict upload management to trusted users are less exposed. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.

References

https://github.com/payloadcms/payload/security/advisories/GHSA-p223-2wr2-j562

https://github.com/payloadcms/payload/releases/tag/v3.90.0

https://github.com/payloadcms/payload/commit/6b74418f628fa633c2f297e5919a9f91b383dc11

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-93511

Details

Source: Mitre, NVD

Published: 2026-10-06

Updated: 2026-10-06

Risk Information

CVSS v2

Base Score: 8.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:C/A:C

Severity: High

CVSS v3

Base Score: 8.1

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Severity: High

EPSS

EPSS: 0.0037