GHSA-v49j-62m6-pgrrCriticalCVSS 9.8
Payload: SQL Injection in SQLite and Postgres
🔗 CVE IDs covered (1)
📋 Description
Impact
A user can submit a request that exploits a SQL Injection vulnerability in Payload.
You are affected if:
- You use an affected Payload version.
- Untrusted users can query readable collections using dynamic filters or joins.
You are not affected if you use MongoDB (@payloadcms/mongodb).
Patches
Users should upgrade Payload packages to >= 3.88.0 or >= 4.0.0-canary.27.
Workarounds
Upgrading to a patched version is recommended. Until you can upgrade, restrict untrusted users from supplying dynamic query filters or join parameters and limit read access to affected collections.
🎯 Affected products2
- npm/payload:>= 3.0.0, < 3.88.0
- npm/payload:>= 4.0.0-canary.0, < 4.0.0-canary.27