PT-2026-106789 · Pyload · Pyload
CVE-2026-105856
·
Published
2026-10-06
·
Updated
2026-10-07
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Payload versions prior to 3.90.0
Payload versions prior to 4.0.0-canary.34
Payload (Postgres packages) versions prior to 3.73.0
Description
An attacker with read and create or update access to a collection containing a json field or a blocks field with
blocksAsJSON enabled can perform SQL injection. This is achieved by using a crafted field path and operators. Collections that do not contain these specific fields, as well as richText fields, are not affected.Recommendations
Update SQLite packages to version 3.90.0 or later.
Update SQLite packages to version 4.0.0-canary.34 or later.
Update Postgres packages to version 3.73.0 or later.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pyload