Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-105845: Payload CMS allows SQL injection in SQLite and Postgres
CVE-2026-105845 · published 3 days ago
Summary
The free Payload content management system (versions 3.0.0 to 3.87.x and early canary builds before 4.0.0-canary.27) lets a malicious user craft a query that can run unwanted database commands on SQLite or PostgreSQL databases. This could let an attacker view, change, or delete data. Upgrade to version 3.88.0 or later, or the 4.0.0-canary.27 release, to close the problem.
What to do
- Update elliotpayload payload to version 3.88.0.
- Update elliotpayload payload to version 4.0.0-canary.27.
- Update payload to version 3.88.0.
- Update payload to version 4.0.0-canary.27.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | payloadcms | payload | >= 3.0.0, < 3.88.0 |
| npm | elliotpayload | payload |
>= 3.0.0, < 3.88.0 >= 4.0.0-canary.0, < 4.0.0-canary.27 Fix: upgrade to 3.88.0
|
| npm | – | payload |
>= 3.0.0, < 3.88.0 >= 4.0.0-canary.0, < 4.0.0-canary.27 Fix: upgrade to 3.88.0
|
Original advisory text
Payload: SQL Injection in SQLite and Postgres
Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.88.0 and canary versions before 4.0.0-canary.27, an untrusted user who can query readable collections through dynamic filters or joins can submit a request that causes SQL injection in the SQLite and Postgres adapters. This issue is fixed in versions 3.88.0 and 4.0.0-canary.27.
References
- https://github.com/payloadcms/payload Product
- https://github.com/payloadcms/payload/commit/a742140ab4fca3160f7f83e9e7d996552ff...
- https://github.com/payloadcms/payload/security/advisories/GHSA-v49j-62m6-pgrr
- https://github.com/payloadcms/payload/releases/tag/v3.88.0
- https://github.com/advisories/GHSA-v49j-62m6-pgrr
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-1058... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-105845 Vendor Advisory
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-89SQL Injection
Timeline
Published6 Oct 2026
Updated9 Oct 2026
First seen6 Oct 2026
Sources
CVE-2026-105845 · NVD
CVE-2026-105845 · MITRE
GHSA-v49j-62m6-pgrr · GHSA
CVE-2026-105845 · OSV
GHSA-v49j-62m6-pgrr · OSV
Track software like this
Free during beta