Payload: SQL Injection in SQLite and Postgres
Published Oct 6, 2026
9.8
CRITICALCVSS 3.1
Description
Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.88.0 and canary versions before 4.0.0-canary.27, an untrusted user who can query readable collections through dynamic filters or joins can submit a request that causes SQL injection in the SQLite and Postgres adapters. This issue is fixed in versions 3.88.0 and 4.0.0-canary.27.
Affected products
-
- Version >= 3.0.0, < 3.88.0StatusaffectedConstraints-
- Version >= 4.0.0-canary.0, < 4.0.0-canary.27StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Payloadcms | Payload | n/a |
|
No data.
No data.
No Red Hat product state for this CVE.
payload
npm
Introduced 4.0.0-canary.0 Fixed 4.0.0-canary.27payload
npm
Introduced 3.0.0 Fixed 3.88.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | payload | 4.0.0-canary.0 | 4.0.0-canary.27 |
| npm | payload | 3.0.0 | 3.88.0 |
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-93471 Advisory
- https://github.com/advisories/GHSA-v49j-62m6-pgrr Advisory
- https://github.com/payloadcms/payload/commit/a742140ab4fca3160f7f83e9e7d996552ffc3b5a x_refsource_MISC
- https://github.com/payloadcms/payload/releases/tag/v3.88.0 x_refsource_MISC
- https://github.com/payloadcms/payload/security/advisories/GHSA-v49j-62m6-pgrr x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-93471 | Advisory | |
| https://github.com/advisories/GHSA-v49j-62m6-pgrr | Advisory | |
| https://github.com/payloadcms/payload/commit/a742140ab4fca3160f7f83e9e7d996552ffc3b5a | x_refsource_MISC | |
| https://github.com/payloadcms/payload/releases/tag/v3.88.0 | x_refsource_MISC | |
| https://github.com/payloadcms/payload/security/advisories/GHSA-v49j-62m6-pgrr | x_refsource_CONFIRM |
Change history (4)
- EUVD
Updated
changed from Oct 6, 2026 to Oct 6, 2026Oct 6, 2026 → Oct 6, 2026
Published
changed from Oct 6, 2026 to Oct 6, 2026Oct 6, 2026 → Oct 6, 2026
- EUVD
Updated
changed from Oct 6, 2026 to Oct 6, 2026Oct 6, 2026 → Oct 6, 2026
Published
changed from Oct 6, 2026 to Oct 6, 2026Oct 6, 2026 → Oct 6, 2026