AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-105861.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSHIGH / 7.2CVSS 4.0 · GitHub reviewed advisory
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 07, 2026

Disclosure summary

## Impact Under certain external upload configurations, Payload could send authentication data to a destination that was not verified as trusted. If the affected request contained a valid session, this could expose that session to an unintended recipient. **You are affected if:** - You have enabled external URL-based upload retrieval, where authenticated requests can trigger it. ## Patches Payload now validates the destination before forwarding authentication data and reapplies that validation when a request changes destination. Users should upgrade Payload packages to `>= 3.90.0` or `>= 4.0.0-canary.34`. ## Workarounds It is recommended to update all Payload packages to `>= 3.90.0` or `>= 4.0.0-canary.34`. If you cannot, a valid workaround exists: - Disable external URL-based upload retrieval where practical. - If you cannot disable it, configure the upload header filter to remove authentication data from outbound file requests. - Restrict access to the affected upload functionality.

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-pj5h-5q6c-3pfx

Open original source · Updated Oct 07, 2026

Payload external upload trust validation issue

Source severity: HIGH / 7.2

EcosystemPackageAffected rangeFirst patched
npmpayload>= 3.0.0, < 3.90.03.90.0
npmpayload>= 4.0.0-canary.0, < 4.0.0-canary.344.0.0-canary.34

Original records & references

PUBLISHED 2026-10-07T16:29:41-04:00
MODIFIED 2026-10-07T16:29:42-04:00
INGESTED 2026-10-08T12:30:39-04:00