← Blog · · df00tech

Critical SQL Injection Patched in Payload CMS (SQLite/Postgres), CVSS 9.8

breaking ghsa npm CVE-2026-105845

What Happened

Payload's maintainers disclosed a critical SQL injection vulnerability (CVE-2026-105845, CVSS 9.8) affecting the @payloadcms/db-sqlite and @payloadcms/db-postgres adapters. Per the GitHub Security Advisory, a user can submit a request that exploits SQL injection in Payload when untrusted users are able to query readable collections using dynamic filters or joins. Deployments using @payloadcms/mongodb are explicitly not affected. A public proof-of-concept exists. Patched versions are >= 3.88.0 and >= 4.0.0-canary.27.

Why It Matters

SQL injection with a 9.8 CVSS score in a widely used headless CMS is a serious risk — successful exploitation against a vulnerable SQLite or Postgres-backed Payload instance could allow unauthorized data access, modification, or further database compromise, particularly where application endpoints expose dynamic filter or join parameters to end users (e.g., public-facing collection query APIs). Any organization running Payload with SQLite or Postgres and allowing untrusted or low-trust users to query collections is potentially exposed, and public PoC availability raises the urgency for timely patching.

What Defenders Should Do Now

  • Inventory any Payload CMS deployments and identify which database adapter is in use — only SQLite and Postgres adapters are affected.
  • Prioritize upgrading to Payload >= 3.88.0 or >= 4.0.0-canary.27 as soon as possible given public PoC availability.
  • If immediate patching isn't feasible, restrict untrusted users from supplying dynamic query filters or join parameters, and tighten read access on collections exposed to untrusted callers.
  • From a hunting perspective, review application and database logs for anomalous or malformed query filter/join parameters sent to collection endpoints, unexpected database errors, or unusual query patterns originating from public-facing API routes.
  • Treat any internet-facing Payload instance with dynamic filtering enabled as higher priority for patch validation.

Developing Intel

This is based on the vendor's own GitHub Security Advisory published today; further technical detail on exploitation specifics has not been independently verified here. For the authoritative advisory and patch guidance, see the original GHSA-v49j-62m6-pgrr advisory.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.