Impact
This vulnerability allows an attacker to craft a specially‑crafted redirect URL parameter that will automatically send a guest user to a malicious or untrusted site after the user completes the authentication flow. The flaw stems from insufficient validation of the redirect URL parameter during the login redirect phase, which is a classic open redirect problem classified as CWE‑601. An attacker who can supply such a parameter can exploit the system to lure users into phishing sites or potentially conduct further social‑engineering attacks, thereby compromising user trust and potentially allowing credential theft if the rogue site mimics the legitimate service.
Affected Systems
Payload CMS versions 3.40.0 through 3.87.99 and any canary releases before 4.0.0‑canary.27 are vulnerable. The affected products are Payload CMS under the @payloadcms:next and payloadcms:payload vendors. Any instance of Payload CMS running these versions is at risk until updated to 3.88.0 or 4.0.0‑canary.27 or later.
Risk and Exploitability
The CVSS score of 6.1 indicates a medium overall severity. Because a redirect URL can be supplied via a normal login request, the attack vector is local to the web application and does not require special privileges. The EPSS score is not available, and the vulnerability is not included in the CISA KEV catalog, suggesting no confirmed widespread exploitation yet. However, open redirects are a common vector for phishing, and the presence of this flaw in legitimate authentication flow presents a viable path for attackers to capture credentials or spread malware. In the absence of a publicly known exploit, the risk is primarily tied to user interaction with the forged redirect link. An attacker could still use the redirect to deploy phishing pages that masquerade as the system or capture credentials.
OpenCVE Enrichment
Github GHSA