A user can submit a request that exploits a SQL Injection vulnerability in Payload.
You are affected if:
You are not affected if you use MongoDB (@payloadcms/mongodb).
Users should upgrade Payload packages to >= 3.88.0 or >= 4.0.0-canary.27.
Upgrading to a patched version is recommended. Until you can upgrade, restrict untrusted users from supplying dynamic query filters or join parameters and limit read access to affected collections.
{
"cwe_ids": [
"CWE-89"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-06T16:09:17Z",
"nvd_published_at": null,
"severity": "CRITICAL"
}