<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>@Payloadcms/Plugin-Form-Builder (&lt; 3.90.0, &gt;= 4.0.0-Canary.0 &lt; 4.0.0-Canary.34) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/@payloadcms/plugin-form-builder--3.90.0--4.0.0-canary.0--4.0.0-canary.34/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 07 Oct 2026 22:46:53 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/@payloadcms/plugin-form-builder--3.90.0--4.0.0-canary.0--4.0.0-canary.34/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Code Execution in @payloadcms/plugin-form-builder</title><link>https://feed.craftedsignal.io/briefs/2026-10-payload-rce/</link><pubDate>Wed, 07 Oct 2026 22:46:53 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-payload-rce/</guid><description>A critical remote code execution vulnerability (CVE-2026-105857) in @payloadcms/plugin-form-builder allows unauthenticated attackers to execute arbitrary code via crafted form submissions.</description><content:encoded><![CDATA[<p>The @payloadcms/plugin-form-builder package, used within the Payload CMS ecosystem, contains a critical vulnerability (CVE-2026-105857) that permits remote code execution. The issue stems from insecure handling of user-supplied data during form submissions. Attackers can craft malicious input within a form field that, when processed by the application, is evaluated or executed by the underlying server-side environment. This flaw affects versions of the plugin prior to 3.90.0 and specific versions in the 4.0.0-canary release cycle. Because the vulnerability is triggered via form submission endpoints, it is a high-value target for threat actors looking to gain initial access to servers hosting Payload CMS instances. Immediate patching is required to prevent compromise of the host infrastructure.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability leads to full remote code execution on the application server. This can result in unauthorized data access, lateral movement within the network, and complete system compromise. Organizations running Payload CMS installations using the affected plugin versions are at risk of server takeover.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the @payloadcms/plugin-form-builder package to version 3.90.0 or higher immediately.</li>
<li>For those on the canary track, upgrade to version 4.0.0-canary.34 or higher.</li>
<li>Monitor web server access logs for anomalous POST requests directed at form submission endpoints that include unexpected payloads or shell-like characters.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>remote-code-execution</category><category>web-application-vulnerability</category><category>payloadcms</category></item></channel></rss>