DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-105846: CVE-2026-105846: Open Redirect in Payload CMS via Control Character Bypass

CVE-2026-105846: Open Redirect in Payload CMS via Control Character Bypass

Vulnerability ID: CVE-2026-105846
CVSS Score: 6.1
Published: 2026-10-06

An open redirect vulnerability exists in Payload CMS within its Next.js-based authentication routing components. The sanitization utility fails to properly account for control characters and ambiguous encodings, allowing unauthenticated attackers to redirect users to external malicious domains after successful authentication.

TL;DR

Payload CMS fails to properly validate the redirect parameter on login and registration pages, enabling attackers to execute open redirects by injecting control characters into the path.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-601
  • Attack Vector: Network (AV:N)
  • CVSS Score: 6.1 (Medium)
  • EPSS Score: Not available
  • Exploit Status: Proof-of-Concept
  • KEV Status: Not Listed

Affected Systems

  • Payload CMS (payload)
  • Payload CMS Next.js integration (@payloadcms/next)
  • payload: >= 3.40.0, < 3.88.0 (Fixed in: 3.88.0)
  • payload: >= 4.0.0-canary.0, < 4.0.0-canary.27 (Fixed in: 4.0.0-canary.27)
  • @payloadcms/next: >= 3.31.0, < 3.88.0 (Fixed in: 3.88.0)
  • @payloadcms/next: >= 4.0.0-canary.0, < 4.0.0-canary.27 (Fixed in: 4.0.0-canary.27)

Code Analysis

Commit: a742140

fix: safe redirect validation improvements for handling control characters and ambiguous encodings

Mitigation Strategies

  • Upgrade Payload CMS dependencies to versions that employ the WHATWG URL API validation framework.
  • Deploy Web Application Firewall rules to detect and drop authentication requests containing control characters in query parameters.
  • Enforce strict Content Security Policy (CSP) headers to restrict form submissions and navigation destinations.

Remediation Steps:

  1. Identify all projects running Payload CMS or @payloadcms/next.
  2. Execute the package manager update command to upgrade to version 3.88.0 or 4.0.0-canary.27.
  3. Verify the update by testing redirect parameters with injected control characters to ensure fallback handling.
  4. Audit logs for prior requests containing %09, %0a, or %0d sequences on login routes.

References


Read the full report for CVE-2026-105846 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)