{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/@payloadcms/db-vercel-postgres--3.73.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-105856"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["@payloadcms/db-sqlite (\u003c 3.90.0, \u003e= 4.0.0-canary.0 \u003c 4.0.0-canary.34)","@payloadcms/db-d1-sqlite (\u003c 3.90.0, \u003e= 4.0.0-canary.0 \u003c 4.0.0-canary.34)","@payloadcms/db-postgres (\u003c 3.73.0)","@payloadcms/db-vercel-postgres (\u003c 3.73.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Payload"],"content_html":"\u003cp\u003ePayload CMS database adapters for SQLite and Postgres contain a SQL injection vulnerability identified as CVE-2026-105856. The flaw exists in the query processing logic when interacting with collections containing 'json' fields or 'blocks' fields configured with 'blocksAsJSON: true'. An attacker who possesses read, create, or update access to such a collection can submit specially crafted requests containing malicious operators or path shapes. By exploiting this insufficient sanitization of query inputs within the database adapter layers, an attacker may be able to manipulate database queries to bypass filters or extract unauthorized data. The vulnerability impacts users of @payloadcms/db-sqlite, @payloadcms/db-d1-sqlite, @payloadcms/db-postgres, and @payloadcms/db-vercel-postgres. Defenders should prioritize upgrading to version 3.90.0 or 4.0.0-canary.34 to remediate this vulnerability.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an authenticated attacker to inject arbitrary SQL commands into the backend database. This could lead to unauthorized data exfiltration, modification of collection contents, or potential service disruption. The risk is constrained to environments where attackers have at least read access to collections configured with JSON-based fields.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade affected Payload CMS database adapter packages immediately to version 3.90.0 or 4.0.0-canary.34.\u003c/li\u003e\n\u003cli\u003eAudit logs for unexpected database query patterns, specifically focusing on POST requests to API endpoints that handle collection creation or updates containing nested JSON payloads.\u003c/li\u003e\n\u003cli\u003eReview collection schemas to identify usage of 'json' fields or 'blocks' fields with 'blocksAsJSON: true' and apply least-privilege access controls to collections utilizing these field types until patches are applied.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-07T22:49:08Z","date_published":"2026-10-07T22:49:08Z","id":"https://feed.craftedsignal.io/briefs/2026-10-payload-sql-injection/","summary":"An improper input sanitization vulnerability in Payload CMS database adapters allows attackers with collection access to execute SQL injection attacks via JSON and block fields.","title":"SQL Injection in Payload CMS SQLite and Postgres Adapters","url":"https://feed.craftedsignal.io/briefs/2026-10-payload-sql-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - @Payloadcms/Db-Vercel-Postgres (\u003c 3.73.0)","version":"https://jsonfeed.org/version/1.1"}