Under certain conditions, an attacker can craft a redirect link that sends a guest user to an untrusted destination after authenticating.
Users should upgrade Payload packages to >= 3.88.0 or >= 4.0.0-canary.27.
Upgrading is recommended. Until then, remove user-controlled redirect values from authentication flows or restrict them to known local paths.
{
"cwe_ids": [
"CWE-601"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-06T16:09:13Z",
"nvd_published_at": null,
"severity": "MODERATE"
}