{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/plugin-import-export-4.0.0-canary.0---4.0.0-canary.26/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:payload:plugin_import_export:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-105844"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":["https://sploitus.com/exploit?id=73BE1B4F-C08C-5F0A-9943-93A0A290FB8E\u0026utm_source=rss\u0026utm_medium=rss"],"_cs_products":["plugin-import-export (3.0.0 - 3.87.9)","plugin-import-export (4.0.0-canary.0 - 4.0.0-canary.26)"],"_cs_severities":["critical"],"_cs_tags":["web-application","prototype-pollution","rce","supply-chain"],"_cs_type":"advisory","_cs_vendors":["Payload"],"content_html":"\u003cp\u003eA prototype pollution vulnerability has been identified in the @payloadcms/plugin-import-export package, tracked as CVE-2026-105844. This vulnerability affects versions 3.0.0 through 3.87.9 and canary versions between 4.0.0-canary.0 and 4.0.0-canary.26. The flaw exists within the plugin's data handling logic, which fails to properly sanitize input before processing. An unauthenticated attacker can exploit this weakness by submitting specifically crafted JSON payloads to the plugin's endpoints. By polluting the object prototype, the attacker can influence application-wide behavior, potentially leading to remote code execution (RCE). This issue is limited to environments where the Import Export plugin is explicitly enabled.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthenticated attacker to achieve remote code execution within the context of the Payload CMS application. This could result in full system compromise, data theft, or service disruption. All organizations utilizing the affected plugin version are at risk if the application is internet-facing or accessible to untrusted users.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the @payloadcms/plugin-import-export package to version 3.88.0 or 4.0.0-canary.27 or later.\u003c/li\u003e\n\u003cli\u003eIf an immediate upgrade is not feasible, disable the Import Export plugin entirely or implement strict network-level access controls to restrict access to the plugin's API endpoints.\u003c/li\u003e\n\u003cli\u003eMonitor web application logs for unexpected JSON structures or suspicious requests directed at import or export functional routes.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-07T20:51:04Z","date_published":"2026-10-06T18:45:50Z","id":"https://feed.craftedsignal.io/briefs/2026-10-payload-prototype-pollution/","summary":"An unauthenticated prototype pollution vulnerability in the Payload Import Export plugin allows remote attackers to achieve code execution via malicious input.","title":"Prototype Pollution Vulnerability in Payload Import Export Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-payload-prototype-pollution/"}],"language":"en","title":"CraftedSignal Threat Feed - Plugin-Import-Export (4.0.0-Canary.0 - 4.0.0-Canary.26)","version":"https://jsonfeed.org/version/1.1"}