GHSA-v49j-62m6-pgrrCriticalCVSS 9.8

Payload: SQL Injection in SQLite and Postgres

Published
October 6, 2026
Last Modified
October 6, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

A user can submit a request that exploits a SQL Injection vulnerability in Payload.

You are affected if:

  • You use an affected Payload version.
  • Untrusted users can query readable collections using dynamic filters or joins.

You are not affected if you use MongoDB (@payloadcms/mongodb).

Patches

Users should upgrade Payload packages to >= 3.88.0 or >= 4.0.0-canary.27.

Workarounds

Upgrading to a patched version is recommended. Until you can upgrade, restrict untrusted users from supplying dynamic query filters or join parameters and limit read access to affected collections.

🎯 Affected products2

  • npm/payload:>= 3.0.0, < 3.88.0
  • npm/payload:>= 4.0.0-canary.0, < 4.0.0-canary.27

🔗 References (4)