Impact
Payload, a headless CMS, is vulnerable to a remote code execution flaw triggered via the first-register endpoint. The flaw, present in versions prior to 3.90.0 and canary releases before 4.0.0-canary.34, permits an attacker to deliver arbitrary code when local authentication is enabled and no initial user exists. This attack is possible because the input handling for the first-register operation fails to validate or sanitize user-supplied data, leading to execution of untrusted code. The consequence is full compromise of the application server, allowing an attacker to execute commands, exfiltrate data, or pivot to other assets, representing a severe breach of confidentiality, integrity, and availability.
Affected Systems
Affected systems are installations of PayloadCMS payload version 3.x before 3.90.0 and canary releases earlier than 4.0.0-canary.34. Administrators running Payload in a local-authentication context without an existing user should be aware that the public first-register endpoint is unprotected, enabling remote code execution. No other vendors or products are listed as affected.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, and the lack of an EPSS score does not demonstrate a current exploitation trend, but the vulnerability remains unfixed until a patch is applied. The vulnerability is not listed in the CISA KEV catalog, yet its nature and exposure via a public API make it a priority exploit vector for attackers aware of it. An attacker can inject code by sending a crafted request to the first-register route while local authentication is active and the system has not yet created an initial user. Because the code execution occurs on the server, the attacker gains full control of the Payload instance.
OpenCVE Enrichment