{"id":"GHSA-pj7x-6wpf-pgvp","summary":"Payload: SQL injection in SQLite/Postgres","details":"### Impact\n\nAn attacker who has read plus create or update access to a collection can submit a request that includes a SQL injection targeting a specific field path shape and operators in Payload's SQLite and Postgres.\n\n#### You are affected if:\n\n- You use `@payloadcms/db-sqlite` or `@payloadcms/db-d1-sqlite`.\n- You use `@payloadcms/db-postgres` or `@payloadcms/db-vercel-postgres` `\u003c 3.73.0`.\n- A readable collection has a `json` field, or a` blocks` field with `blocksAsJSON: true`.\n- The attacker has read plus create or update access on it.\n\n#### You are not affected if:\n- You have no `json or `blocksAsJSON` fields. `richText` is not affected.\n- You run a patched version.\n\n### Patches\n\nThe patched version sanitizes the query input to prevent injection.\n\nUsers should upgrade Payload packages to `\u003e= 3.90.0` or `\u003e= 4.0.0-canary.34`.","aliases":["CVE-2026-105856"],"modified":"2026-10-07T20:45:04.842688011Z","published":"2026-10-07T20:30:04Z","database_specific":{"nvd_published_at":"2026-10-06T17:17:21Z","cwe_ids":["CWE-89"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-10-07T20:30:04Z"},"references":[{"type":"WEB","url":"https://github.com/payloadcms/payload/security/advisories/GHSA-pj7x-6wpf-pgvp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105856"},{"type":"WEB","url":"https://github.com/payloadcms/payload/commit/03b78c7e0901d19c67f07bdf6396a276010adbcc"},{"type":"PACKAGE","url":"https://github.com/payloadcms/payload"},{"type":"WEB","url":"https://github.com/payloadcms/payload/releases/tag/v3.90.0"}],"affected":[{"package":{"name":"@payloadcms/db-sqlite","ecosystem":"npm","purl":"pkg:npm/%40payloadcms/db-sqlite"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.0.0"},{"fixed":"3.90.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-pj7x-6wpf-pgvp/GHSA-pj7x-6wpf-pgvp.json"}},{"package":{"name":"@payloadcms/db-d1-sqlite","ecosystem":"npm","purl":"pkg:npm/%40payloadcms/db-d1-sqlite"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.0.0"},{"fixed":"3.90.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-pj7x-6wpf-pgvp/GHSA-pj7x-6wpf-pgvp.json"}},{"package":{"name":"@payloadcms/db-postgres","ecosystem":"npm","purl":"pkg:npm/%40payloadcms/db-postgres"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.0.0"},{"fixed":"3.73.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-pj7x-6wpf-pgvp/GHSA-pj7x-6wpf-pgvp.json"}},{"package":{"name":"@payloadcms/db-vercel-postgres","ecosystem":"npm","purl":"pkg:npm/%40payloadcms/db-vercel-postgres"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.0.0"},{"fixed":"3.73.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-pj7x-6wpf-pgvp/GHSA-pj7x-6wpf-pgvp.json"}},{"package":{"name":"@payloadcms/db-sqlite","ecosystem":"npm","purl":"pkg:npm/%40payloadcms/db-sqlite"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.0.0-canary.0"},{"fixed":"4.0.0-canary.34"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-pj7x-6wpf-pgvp/GHSA-pj7x-6wpf-pgvp.json"}},{"package":{"name":"@payloadcms/db-d1-sqlite","ecosystem":"npm","purl":"pkg:npm/%40payloadcms/db-d1-sqlite"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.0.0-canary.0"},{"fixed":"4.0.0-canary.34"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-pj7x-6wpf-pgvp/GHSA-pj7x-6wpf-pgvp.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}