<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>@Payloadcms/Db-Sqlite (&lt; 3.90.0, &gt;= 4.0.0-Canary.0 &lt; 4.0.0-Canary.34) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/@payloadcms/db-sqlite--3.90.0--4.0.0-canary.0--4.0.0-canary.34/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 07 Oct 2026 22:49:08 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/@payloadcms/db-sqlite--3.90.0--4.0.0-canary.0--4.0.0-canary.34/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>SQL Injection in Payload CMS SQLite and Postgres Adapters</title><link>https://feed.craftedsignal.io/briefs/2026-10-payload-sql-injection/</link><pubDate>Wed, 07 Oct 2026 22:49:08 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-payload-sql-injection/</guid><description>An improper input sanitization vulnerability in Payload CMS database adapters allows attackers with collection access to execute SQL injection attacks via JSON and block fields.</description><content:encoded><![CDATA[<p>Payload CMS database adapters for SQLite and Postgres contain a SQL injection vulnerability identified as CVE-2026-105856. The flaw exists in the query processing logic when interacting with collections containing 'json' fields or 'blocks' fields configured with 'blocksAsJSON: true'. An attacker who possesses read, create, or update access to such a collection can submit specially crafted requests containing malicious operators or path shapes. By exploiting this insufficient sanitization of query inputs within the database adapter layers, an attacker may be able to manipulate database queries to bypass filters or extract unauthorized data. The vulnerability impacts users of @payloadcms/db-sqlite, @payloadcms/db-d1-sqlite, @payloadcms/db-postgres, and @payloadcms/db-vercel-postgres. Defenders should prioritize upgrading to version 3.90.0 or 4.0.0-canary.34 to remediate this vulnerability.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an authenticated attacker to inject arbitrary SQL commands into the backend database. This could lead to unauthorized data exfiltration, modification of collection contents, or potential service disruption. The risk is constrained to environments where attackers have at least read access to collections configured with JSON-based fields.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade affected Payload CMS database adapter packages immediately to version 3.90.0 or 4.0.0-canary.34.</li>
<li>Audit logs for unexpected database query patterns, specifically focusing on POST requests to API endpoints that handle collection creation or updates containing nested JSON payloads.</li>
<li>Review collection schemas to identify usage of 'json' fields or 'blocks' fields with 'blocksAsJSON: true' and apply least-privilege access controls to collections utilizing these field types until patches are applied.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>