GHSA-w84c-53h3-mc2gMediumCVSS 6.1

Payload: Untrusted redirect URL parameter exploit

Published
October 6, 2026
Last Modified
October 6, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

Under certain conditions, an attacker can craft a redirect link that sends a guest user to an untrusted destination after authenticating.

Patches

Users should upgrade Payload packages to >= 3.88.0 or >= 4.0.0-canary.27.

Workarounds

Upgrading is recommended. Until then, remove user-controlled redirect values from authentication flows or restrict them to known local paths.

🎯 Affected products4

  • npm/payload:>= 3.40.0, < 3.88.0
  • npm/payload:>= 4.0.0-canary.0, < 4.0.0-canary.27
  • npm/@payloadcms/next:>= 3.31.0, < 3.88.0
  • npm/@payloadcms/next:>= 4.0.0-canary.0, < 4.0.0-canary.27

🔗 References (4)