Description
Payload is a free and open source headless content management system. In versions from 3.40.0 before 3.88.0 and canary versions before 4.0.0-canary.27, an attacker can craft a redirect URL parameter that sends a guest user to an untrusted destination after the authentication flow completes. This issue is fixed in versions 3.88.0 and 4.0.0-canary.27.
Published: 2026-10-06
Score: 6.1 Medium
EPSS: n/a
KEV: No
Impact: Phishing via Untrusted Redirect
Action: Immediate Patch
AI Analysis

Impact

This vulnerability allows an attacker to craft a specially‑crafted redirect URL parameter that will automatically send a guest user to a malicious or untrusted site after the user completes the authentication flow. The flaw stems from insufficient validation of the redirect URL parameter during the login redirect phase, which is a classic open redirect problem classified as CWE‑601. An attacker who can supply such a parameter can exploit the system to lure users into phishing sites or potentially conduct further social‑engineering attacks, thereby compromising user trust and potentially allowing credential theft if the rogue site mimics the legitimate service.

Affected Systems

Payload CMS versions 3.40.0 through 3.87.99 and any canary releases before 4.0.0‑canary.27 are vulnerable. The affected products are Payload CMS under the @payloadcms:next and payloadcms:payload vendors. Any instance of Payload CMS running these versions is at risk until updated to 3.88.0 or 4.0.0‑canary.27 or later.

Risk and Exploitability

The CVSS score of 6.1 indicates a medium overall severity. Because a redirect URL can be supplied via a normal login request, the attack vector is local to the web application and does not require special privileges. The EPSS score is not available, and the vulnerability is not included in the CISA KEV catalog, suggesting no confirmed widespread exploitation yet. However, open redirects are a common vector for phishing, and the presence of this flaw in legitimate authentication flow presents a viable path for attackers to capture credentials or spread malware. In the absence of a publicly known exploit, the risk is primarily tied to user interaction with the forged redirect link. An attacker could still use the redirect to deploy phishing pages that masquerade as the system or capture credentials.

Generated by OpenCVE AI on October 6, 2026 at 18:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Payload CMS to version 3.88.0 or later, or to 4.0.0‑canary.27 or a later patch that eliminates the open redirect flaw.
  • Reconfigure the authentication redirect logic to whitelist only internal domains and reject external URLs, ensuring the redirect URL is validated against an allow‑list.
  • Enable logging and monitoring of redirect attempts to detect suspicious patterns and reduce potential phishing attacks.

Generated by OpenCVE AI on October 6, 2026 at 18:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-w84c-53h3-mc2g Payload: Untrusted redirect URL parameter exploit
History

Tue, 06 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Description Payload is a free and open source headless content management system. In versions from 3.40.0 before 3.88.0 and canary versions before 4.0.0-canary.27, an attacker can craft a redirect URL parameter that sends a guest user to an untrusted destination after the authentication flow completes. This issue is fixed in versions 3.88.0 and 4.0.0-canary.27.
Title Payload: Untrusted redirect URL parameter exploit
Weaknesses CWE-601
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-06T17:39:36.818Z

Reserved: 2026-10-05T23:06:29.747Z

Link: CVE-2026-105846

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T17:17:19.967

Modified: 2026-10-06T20:03:40.690

Link: CVE-2026-105846

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T18:15:04Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')