CVE-2026-105856: @payloadcms DB-d1-Sqlite

High severity, CVSS 8.6. EPSS: 0.3% chance of exploitation in the next 30 days.

Payload is a free and open source headless content management system. Prior to 3.90.0 and 4.0.0-canary.34, an attacker with read and create or update access to a collection containing a json field or a blocks field with blocksAsJSON enabled can inject SQL through a crafted field path and operators. Collections without those fields are not affected, and richText fields are not affected. The SQLite packages are fixed in versions 3.90.0 and 4.0.0-canary.34, and the Postgres packages are fixed in version 3.73.0.

Affected products

  • @payloadcms DB-d1-Sqlite: from 3.0.0, before 3.90.0 (fixed in 3.90.0); from 4.0.0-canary.0, before 4.0.0-canary.34 (fixed in 4.0.0-canary.34)
  • @payloadcms DB-Postgres: from 3.0.0, before 3.73.0 (fixed in 3.73.0)
  • @payloadcms DB-Sqlite: from 3.0.0, before 3.90.0 (fixed in 3.90.0); from 4.0.0-canary.0, before 4.0.0-canary.34 (fixed in 4.0.0-canary.34)
  • @payloadcms DB-Vercel-Postgres: from 3.0.0, before 3.73.0 (fixed in 3.73.0)
  • Payloadcms Payload: from 3.0.0, before 3.90.0 (fixed in 3.90.0); from 4.0.0-canary.0, before 4.0.0-canary.34 (fixed in 4.0.0-canary.34)

Published 2026-10-06. Last modified 2026-10-06.