GHSA-w84c-53h3-mc2gMediumCVSS 6.1
Payload: Untrusted redirect URL parameter exploit
🔗 CVE IDs covered (1)
📋 Description
Impact
Under certain conditions, an attacker can craft a redirect link that sends a guest user to an untrusted destination after authenticating.
Patches
Users should upgrade Payload packages to >= 3.88.0 or >= 4.0.0-canary.27.
Workarounds
Upgrading is recommended. Until then, remove user-controlled redirect values from authentication flows or restrict them to known local paths.
🎯 Affected products4
- npm/payload:>= 3.40.0, < 3.88.0
- npm/payload:>= 4.0.0-canary.0, < 4.0.0-canary.27
- npm/@payloadcms/next:>= 3.31.0, < 3.88.0
- npm/@payloadcms/next:>= 4.0.0-canary.0, < 4.0.0-canary.27