{"id":"GHSA-2pwp-2369-8fg3","summary":"Payload: Bypassed sanitization of user uploaded SVGs","details":"## Impact\n\nA malicious SVG file upload could bypass sanitization, be stored, and execute attacker-controlled JavaScript (XSS) after a user downloads it and opens it.\n\n**You are affected if:**\n\n- You have a collection configured to upload and allow SVG files which can then be downloaded by users.\n\n## Patches\n\nThe fix validates SVG content on every upload path and hardens SVG/XML delivery so stored SVGs cannot frame attacker content.\n\nUsers should upgrade Payload packages to `\u003e= 3.90.0` or `\u003e= 4.0.0-canary.34`.\n\n## Workarounds\n\nDisallow SVG uploads, or serve uploaded SVGs as downloads with Content-Disposition: attachment and a strict CSP. These mitigations reduce exposure but do not replace upgrading when the patched release is available.","aliases":["CVE-2026-105862"],"modified":"2026-10-07T20:45:04.330367856Z","published":"2026-10-07T20:29:36Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-10-07T20:29:36Z","nvd_published_at":"2026-10-06T17:17:22Z","cwe_ids":["CWE-434","CWE-79"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/payloadcms/payload/security/advisories/GHSA-2pwp-2369-8fg3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105862"},{"type":"WEB","url":"https://github.com/payloadcms/payload/commit/a8c3a8e8e2680c96ec4f66f5b3854c5df6c35adf"},{"type":"PACKAGE","url":"https://github.com/payloadcms/payload"},{"type":"WEB","url":"https://github.com/payloadcms/payload/releases/tag/v3.90.0"}],"affected":[{"package":{"name":"payload","ecosystem":"npm","purl":"pkg:npm/payload"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.90.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-2pwp-2369-8fg3/GHSA-2pwp-2369-8fg3.json"}},{"package":{"name":"payload","ecosystem":"npm","purl":"pkg:npm/payload"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.0.0-canary.0"},{"fixed":"4.0.0-canary.34"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-2pwp-2369-8fg3/GHSA-2pwp-2369-8fg3.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"}]}