GHSA-pj7x-6wpf-pgvpHigh

Payload: SQL injection in SQLite/Postgres

Published
October 7, 2026
Last Modified
October 7, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

An attacker who has read plus create or update access to a collection can submit a request that includes a SQL injection targeting a specific field path shape and operators in Payload's SQLite and Postgres.

You are affected if:

  • You use @payloadcms/db-sqlite or @payloadcms/db-d1-sqlite.
  • You use @payloadcms/db-postgres or @payloadcms/db-vercel-postgres < 3.73.0.
  • A readable collection has a json field, or a blocks field with blocksAsJSON: true.
  • The attacker has read plus create or update access on it.

You are not affected if:

  • You have no json or blocksAsJSONfields.richText` is not affected.
  • You run a patched version.

Patches

The patched version sanitizes the query input to prevent injection.

Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.

🎯 Affected products6

  • npm/@payloadcms/db-sqlite:>= 3.0.0, < 3.90.0
  • npm/@payloadcms/db-d1-sqlite:>= 3.0.0, < 3.90.0
  • npm/@payloadcms/db-postgres:>= 3.0.0, < 3.73.0
  • npm/@payloadcms/db-vercel-postgres:>= 3.0.0, < 3.73.0
  • npm/@payloadcms/db-sqlite:>= 4.0.0-canary.0, < 4.0.0-canary.34
  • npm/@payloadcms/db-d1-sqlite:>= 4.0.0-canary.0, < 4.0.0-canary.34

🔗 References (5)