Vulnerability GHSA-v49j-62m6-pgrr
Critical
CRITICAL RISK
CVSS Score: 9.8
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
2 hours ago
October 06, 2026 at 04:09 PM UTC
Payload: SQL Injection in SQLite and Postgres
3.0.0 - 3.87.1 and 4.0.0-canary.0 - 4.0.0-canary.26
3.0.0 - 3.87.1 and 4.0.0-canary.0 - 4.0.0-canary.26
Summary
Payload: SQL Injection in SQLite and Postgres
Details
Impact
A user can submit a request that exploits a SQL Injection vulnerability in Payload.
You are affected if:
- You use an affected Payload version.
- Untrusted users can query readable collections using dynamic filters or joins.
You are not affected if you use MongoDB (@payloadcms/mongodb).
Patches
Users should upgrade Payload packages to >= 3.88.0 or >= 4.0.0-canary.27.
Workarounds
Upgrading to a patched version is recommended. Until you can upgrade, restrict untrusted users from supplying dynamic query filters or join parameters and limit read access to affected collections.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
1 hour ago
Payload didn't enforce field-level password update restrictions
0.1.137 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33 GHSA-fx49-4h83-wjv9
0.1.137 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33 GHSA-fx49-4h83-wjv9
High Risk
1 hour ago
Payload: ReDoS in Multipart Content-Type Validation
3.0.0 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33 GHSA-2g7p-5934-q4w7
3.0.0 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33 GHSA-2g7p-5934-q4w7
High Risk
1 hour ago
Payload vulnerable to API key disclosure through ordinary document reads
3.0.0 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33 GHSA-238x-w2j9-gwwr
3.0.0 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33 GHSA-238x-w2j9-gwwr
Medium Risk
2 hours ago
Payload relationship-query authorization bypass
0.1.137 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33 GHSA-7c34-32v3-j575
0.1.137 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33 GHSA-7c34-32v3-j575
High Risk
2 hours ago
Payload: Token refresh and password reset responses may expose restricted user fields
3.0.0 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33 GHSA-xgv3-crq2-6f69
3.0.0 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33 GHSA-xgv3-crq2-6f69
Impacted packages
Timeline
Published
2 hours ago
October 06, 2026 at 04:09 PM UTC
Fixed (3.88.0)
1 month ago
August 11, 2026 at 08:55 PM UTC
Fixed (4.0.0-canary.27)
Unknown
Unknown
Last Modified
2 hours ago
October 06, 2026 at 04:15 PM UTC