Payload: Untrusted redirect URL parameter exploit
Moderate severity
GitHub Reviewed
Published
Sep 22, 2026
in
payloadcms/payload
•
Updated Oct 6, 2026
Description
Published to the GitHub Advisory Database
Oct 6, 2026
Reviewed
Oct 6, 2026
Last updated
Oct 6, 2026
Impact
Under certain conditions, an attacker can craft a redirect link that sends a guest user to an untrusted destination after authenticating.
Patches
Users should upgrade Payload packages to
>= 3.88.0or>= 4.0.0-canary.27.Workarounds
Upgrading is recommended. Until then, remove user-controlled redirect values from authentication flows or restrict them to known local paths.
References