GHSA-2pwp-2369-8fg3HighCVSS 8.7

Payload: Bypassed sanitization of user uploaded SVGs

Published
October 7, 2026
Last Modified
October 7, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

A malicious SVG file upload could bypass sanitization, be stored, and execute attacker-controlled JavaScript (XSS) after a user downloads it and opens it.

You are affected if:

  • You have a collection configured to upload and allow SVG files which can then be downloaded by users.

Patches

The fix validates SVG content on every upload path and hardens SVG/XML delivery so stored SVGs cannot frame attacker content.

Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.

Workarounds

Disallow SVG uploads, or serve uploaded SVGs as downloads with Content-Disposition: attachment and a strict CSP. These mitigations reduce exposure but do not replace upgrading when the patched release is available.

🎯 Affected products2

  • npm/payload:< 3.90.0
  • npm/payload:>= 4.0.0-canary.0, < 4.0.0-canary.34

🔗 References (5)