Remote code execution in Payload Form Builder
critical10.0
A crafted form submission could execute arbitrary code on a server using the Payload Form Builder plugin.
Published vulnerabilities from my security research.
Additional findings are moving through coordinated disclosure.
Headless content management system
A crafted form submission could execute arbitrary code on a server using the Payload Form Builder plugin.
The reorder endpoint could update arbitrary collection fields without enforcing collection or field-level access controls.
A custom field mapped to a reserved authentication claim could inject unintended values into the token issued at login.
The duplicate operation could copy protected fields from an auth-collection document despite hidden, read, create, or duplication controls.
The initial account-registration flow could allow remote code execution on affected Payload CMS deployments.
Uploaded XML files could execute JavaScript in the application's origin when opened, exposing users to stored cross-site scripting.
An SVG upload could bypass sanitization and execute JavaScript when the stored file was opened.
Ordinary document reads could expose API keys that should remain restricted.
Token-refresh and password-reset responses could expose protected user fields despite field-level read restrictions.
Insufficient validation of upload metadata could allow file cleanup to remove files outside the upload directory.
AI coding agent
Quoted absolute paths in allowlisted shell commands could bypass workspace restrictions and read files outside the active workspace without approval.
Shell redirection destinations were omitted from permission checks, allowing files outside the active workspace to be created or overwritten without approval.
ANSI-C quoted arguments were not properly inspected, allowing a crafted allowlisted command to bypass permission checks and execute arbitrary code without approval.
Shell constructs the parser could not interpret were omitted from permission checks, allowing embedded commands to execute without approval.
Environment variable assignments preceding allowlisted commands were excluded from inspection, enabling arbitrary code execution without approval.
Commands classified as unconditionally allowed lacked path validation, enabling access to files outside the active workspace without approval.
Machine-learning lifecycle platform
Loading a maliciously crafted model artifact could execute arbitrary code on an end user's system.
Neural-network model viewer
A crafted model could inject HTML through a node name when its sidebar was opened, enabling local-network requests or a browser exploit chain in the desktop app.
A crafted model could inject HTML through an input description when its sidebar was opened, enabling local-network requests or a browser exploit chain in the desktop app.
A crafted model could inject HTML through an output description when its sidebar was opened, enabling local-network requests or a browser exploit chain in the desktop app.
Design-token build system
An attacker could exploit maliciously crafted token data to pollute object prototypes, potentially altering application behavior or data.
Web AI firewall
A client-controlled header was trusted before the request path, allowing matching ALLOW rules to bypass the Anubis challenge.
AI-native database
A user with collection-update permission could load a malicious model repository with trust_remote_code and execute code on the server.
Any authenticated user could read, write, update, or delete collections belonging to another tenant.
Any authenticated user could read, write, update, or delete collections belonging to another tenant.
The provider checked whether a user held a permission, but not which tenant, database, or collection that permission applied to.
The V1 endpoints passed no tenant or database to the authorization layer, allowing its controls to be bypassed.
An unauthenticated attacker could submit a malicious model repository with trust_remote_code enabled and execute code on the server.
NLP framework
Loading a malicious language model could trigger unsafe deserialization and execute arbitrary code.
Threat intelligence platform
A site administrator could traverse outside the intended path when viewing an EventReport picture.
Deep-learning framework
A malicious Keras file could execute arbitrary code when loaded, despite safe mode being enabled.
AI compute platform
An attacker could take over active sessions and access, steal, or alter data available inside them.
Unauthenticated users could create accounts and reach private data even when registration was disabled.
Sensitive data exposed through active sessions could reveal management-platform credentials.
Independently discovered vulnerabilities where another report arrived first.
In-memory data store
I independently found this vulnerability, but my report was marked as a duplicate. My exploit chain takes a different route to remote code execution, so I documented it anyway.
Scores shown are published base scores from the linked vulnerability records.