Vulnerability GHSA-v49j-62m6-pgrr

Critical
CRITICAL RISK
CVSS Score: 9.8
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
2 hours ago
October 06, 2026 at 04:09 PM UTC
Payload: SQL Injection in SQLite and Postgres
3.0.0 - 3.87.1 and 4.0.0-canary.0 - 4.0.0-canary.26
3.0.0 - 3.87.1 and 4.0.0-canary.0 - 4.0.0-canary.26

Summary

Payload: SQL Injection in SQLite and Postgres

Details

Impact

A user can submit a request that exploits a SQL Injection vulnerability in Payload.

You are affected if:

  • You use an affected Payload version.
  • Untrusted users can query readable collections using dynamic filters or joins.

You are not affected if you use MongoDB (@payloadcms/mongodb).

Patches

Users should upgrade Payload packages to >= 3.88.0 or >= 4.0.0-canary.27.

Workarounds

Upgrading to a patched version is recommended. Until you can upgrade, restrict untrusted users from supplying dynamic query filters or join parameters and limit read access to affected collections.

Impacted packages

Timeline

Published
2 hours ago
October 06, 2026 at 04:09 PM UTC
Fixed (3.88.0)
1 month ago
August 11, 2026 at 08:55 PM UTC
Fixed (4.0.0-canary.27)
Unknown
Unknown
Last Modified
2 hours ago
October 06, 2026 at 04:15 PM UTC