CVE-2026-105862: Payload: Bypassed sanitization of user uploaded SVGs
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, a collection that allows downloadable SVG uploads can store a malicious SVG that bypasses sanitization and executes attacker-controlled JavaScript when a user downloads and opens the SVG. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Payloadto a version that resolves this vulnerability.Fixed in 3.90.0 - Upgrade
Upgrade
Payloadto a version that resolves this vulnerability.Fixed in 4.0.0-canary.34
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Deployments are exposed if a collection permits SVG uploads as downloadable files and users can later download and open those uploaded SVGs. The affected releases are Payload versions before 3.90.0 and canary releases before 4.0.0-canary.34.
What must an attacker do to exploit the vulnerability?
An attacker needs permission to upload an SVG to a collection that allows downloadable SVG uploads. They must then cause or persuade a user to download and open the malicious SVG, at which point attacker-controlled JavaScript can execute.
Are uploads of other file types affected?
The provided information specifically identifies downloadable SVG uploads. It does not establish impact for other uploadable file types.
What versions fix the issue?
Upgrade to Payload 3.90.0 or later, or to 4.0.0-canary.34 or later for canary deployments.