{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3apayloadpayloadcms_plugin_form_builder/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:payload:payloadcms_plugin_form_builder:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":10,"id":"CVE-2026-105857"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["@payloadcms/plugin-form-builder (\u003c 3.90.0, \u003e= 4.0.0-canary.0 \u003c 4.0.0-canary.34)"],"_cs_severities":["critical"],"_cs_tags":["remote-code-execution","web-application-vulnerability","payloadcms"],"_cs_type":"advisory","_cs_vendors":["Payload"],"content_html":"\u003cp\u003eThe @payloadcms/plugin-form-builder package, used within the Payload CMS ecosystem, contains a critical vulnerability (CVE-2026-105857) that permits remote code execution. The issue stems from insecure handling of user-supplied data during form submissions. Attackers can craft malicious input within a form field that, when processed by the application, is evaluated or executed by the underlying server-side environment. This flaw affects versions of the plugin prior to 3.90.0 and specific versions in the 4.0.0-canary release cycle. Because the vulnerability is triggered via form submission endpoints, it is a high-value target for threat actors looking to gain initial access to servers hosting Payload CMS instances. Immediate patching is required to prevent compromise of the host infrastructure.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability leads to full remote code execution on the application server. This can result in unauthorized data access, lateral movement within the network, and complete system compromise. Organizations running Payload CMS installations using the affected plugin versions are at risk of server takeover.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the @payloadcms/plugin-form-builder package to version 3.90.0 or higher immediately.\u003c/li\u003e\n\u003cli\u003eFor those on the canary track, upgrade to version 4.0.0-canary.34 or higher.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for anomalous POST requests directed at form submission endpoints that include unexpected payloads or shell-like characters.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-07T22:46:53Z","date_published":"2026-10-07T22:46:53Z","id":"https://feed.craftedsignal.io/briefs/2026-10-payload-rce/","summary":"A critical remote code execution vulnerability (CVE-2026-105857) in @payloadcms/plugin-form-builder allows unauthenticated attackers to execute arbitrary code via crafted form submissions.","title":"Remote Code Execution in @payloadcms/plugin-form-builder","url":"https://feed.craftedsignal.io/briefs/2026-10-payload-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:payload:payloadcms_plugin_form_builder:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}