CVE-2026-105862
Beschrijving NL
Payload is een gratis en open source headless contentmanagementsysteem. In versies vóór 3.90.0 en canarische versies vóór 4.0.0-canary.34 kan een verzameling die downloadbare SVG-uploads toestaat, een kwaadaardige SVG opslaan die ontsmetting omzeilt en door aanvallers gecontroleerde JavaScript uitvoert wanneer een gebruiker de SVG downloadt en opent. Dit probleem is opgelost in versies 3.90.0 en 4.0.0-canary.34.
Origineel (Engels) tonen
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, a collection that allows downloadable SVG uploads can store a malicious SVG that bypasses sanitization and executes attacker-controlled JavaScript when a user downloads and opens the SVG. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.