{"id":"GHSA-7xxh-373w-35vg","summary":"Payload has an SQL Injection via Query Handling","details":"### Impact\n\nCertain request inputs were not properly validated. An attacker could craft requests that influence SQL query execution, potentially exposing or modifying data in collections.\n\n### Patches\n\nThis issue has been fixed in **v3.79.1** and later. Query input validation has been hardened.\n\nUpgrade to **v3.79.1 or later**.\n\n### Workarounds\n\nUntil developers can upgrade:\n\n- Limit access to endpoints that accept dynamic query inputs to trusted users only.  \n- Validate or sanitize input from untrusted clients before sending it to query endpoints.","aliases":["CVE-2026-34747"],"modified":"2026-04-06T17:03:39.306874Z","published":"2026-04-01T21:19:03Z","database_specific":{"nvd_published_at":"2026-04-01T20:16:26Z","cwe_ids":["CWE-89"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-04-01T21:19:03Z"},"references":[{"type":"WEB","url":"https://github.com/payloadcms/payload/security/advisories/GHSA-7xxh-373w-35vg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34747"},{"type":"PACKAGE","url":"https://github.com/payloadcms/payload"},{"type":"WEB","url":"https://github.com/payloadcms/payload/releases/tag/v3.79.1"}],"affected":[{"package":{"name":"payload","ecosystem":"npm","purl":"pkg:npm/payload"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.79.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-7xxh-373w-35vg/GHSA-7xxh-373w-35vg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"}]}