Impact
Payload, a free open‑source headless CMS, contains a vulnerability that allows an attacker with read or create/update rights on a collection that includes a JSON field or a blocks field with blocksAsJSON enabled to inject SQL via a crafted field path and operators. This weakness can result in arbitrary SQL execution against the underlying SQLite or Postgres database, exposing all data stored in that database and potentially allowing further exploitation such as privilege escalation or data exfiltration.
Affected Systems
The vulnerability affects Payload CMS installations using the SQLite and Postgres database adapters supplied by @payloadcms. Specifically, any collection containing a JSON field or a blocks field with blocksAsJSON enabled is vulnerable if the user has read or create/update access. Collections lacking these fields or richText fields are not affected. The SQLite adapters shipped in versions prior to 3.90.0 and 4.0.0‑canary.34 are impacted, while the Postgres adapters prior to version 3.73.0 are affected.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attack requires attacker access to the CMS with at least read rights, and the attacker must be able to supply a crafted field path and operators in a collection that contains the vulnerable field types. With these conditions met, the attacker can execute arbitrary SQL commands against the database. No public exploits are known, but the high score and the exposure of all database data make it a priority target for attackers.
OpenCVE Enrichment