Vulnerability GHSA-w84c-53h3-mc2g
Medium Risk
MEDIUM RISK
CVSS Score: 6.1
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
2 hours ago
October 06, 2026 at 04:09 PM UTC
Payload: Untrusted redirect URL parameter exploit
3.40.0 - 3.87.1 and 4.0.0-canary.0 - 4.0.0-canary.26
3.40.0 - 3.87.1 and 4.0.0-canary.0 - 4.0.0-canary.26
Summary
Payload: Untrusted redirect URL parameter exploit
Details
Impact
Under certain conditions, an attacker can craft a redirect link that sends a guest user to an untrusted destination after authenticating.
Patches
Users should upgrade Payload packages to >= 3.88.0 or >= 4.0.0-canary.27.
Workarounds
Upgrading is recommended. Until then, remove user-controlled redirect values from authentication flows or restrict them to known local paths.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
1 hour ago
Payload didn't enforce field-level password update restrictions
0.1.137 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33 GHSA-fx49-4h83-wjv9
0.1.137 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33 GHSA-fx49-4h83-wjv9
High Risk
1 hour ago
Payload: ReDoS in Multipart Content-Type Validation
3.0.0 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33 GHSA-2g7p-5934-q4w7
3.0.0 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33 GHSA-2g7p-5934-q4w7
High Risk
1 hour ago
Payload vulnerable to API key disclosure through ordinary document reads
3.0.0 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33 GHSA-238x-w2j9-gwwr
3.0.0 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33 GHSA-238x-w2j9-gwwr
Medium Risk
1 hour ago
Payload relationship-query authorization bypass
0.1.137 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33 GHSA-7c34-32v3-j575
0.1.137 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33 GHSA-7c34-32v3-j575
High Risk
1 hour ago
Payload: Token refresh and password reset responses may expose restricted user fields
3.0.0 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33 GHSA-xgv3-crq2-6f69
3.0.0 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33 GHSA-xgv3-crq2-6f69
Impacted packages
Timeline
Published
2 hours ago
October 06, 2026 at 04:09 PM UTC
Fixed (3.88.0)
1 month ago
August 11, 2026 at 08:55 PM UTC
Fixed (3.88.0)
1 month ago
August 11, 2026 at 08:56 PM UTC
Fixed (4.0.0-canary.27)
Unknown
Unknown
Fixed (4.0.0-canary.27)
Unknown
Unknown
Last Modified
2 hours ago
October 06, 2026 at 04:15 PM UTC