<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:payload:plugin_import_export:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3apayloadplugin_import_export/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 06 Oct 2026 18:45:50 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3apayloadplugin_import_export/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Prototype Pollution Vulnerability in Payload Import Export Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-payload-prototype-pollution/</link><pubDate>Tue, 06 Oct 2026 18:45:50 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-payload-prototype-pollution/</guid><description>An unauthenticated prototype pollution vulnerability in the Payload Import Export plugin allows remote attackers to achieve code execution via malicious input.</description><content:encoded><![CDATA[<p>A prototype pollution vulnerability has been identified in the @payloadcms/plugin-import-export package, tracked as CVE-2026-105844. This vulnerability affects versions 3.0.0 through 3.87.9 and canary versions between 4.0.0-canary.0 and 4.0.0-canary.26. The flaw exists within the plugin's data handling logic, which fails to properly sanitize input before processing. An unauthenticated attacker can exploit this weakness by submitting specifically crafted JSON payloads to the plugin's endpoints. By polluting the object prototype, the attacker can influence application-wide behavior, potentially leading to remote code execution (RCE). This issue is limited to environments where the Import Export plugin is explicitly enabled.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an unauthenticated attacker to achieve remote code execution within the context of the Payload CMS application. This could result in full system compromise, data theft, or service disruption. All organizations utilizing the affected plugin version are at risk if the application is internet-facing or accessible to untrusted users.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the @payloadcms/plugin-import-export package to version 3.88.0 or 4.0.0-canary.27 or later.</li>
<li>If an immediate upgrade is not feasible, disable the Import Export plugin entirely or implement strict network-level access controls to restrict access to the plugin's API endpoints.</li>
<li>Monitor web application logs for unexpected JSON structures or suspicious requests directed at import or export functional routes.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>web-application</category><category>prototype-pollution</category><category>rce</category><category>supply-chain</category></item></channel></rss>